CVE-2023-28785: WordPress Yoast SEO: Local Plugin <= 14.9 is vulnerable to Cross Site Scripting (XSS)
Published May 28, 2023
·Updated
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.9 versions.
Affected Software
1 affected component
Yoast Yoast SEO WordPress<=14.9
Remediation
Information
Update to 15.0 or a higher version.
Event History
May 28, 2023
CVE Published
via MITRE·06:47 PM
Data Sourced
via MITRE·06:47 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-28785?
The severity of CVE-2023-28785 is classified as medium.
2
What is the affected software of CVE-2023-28785?
The affected software of CVE-2023-28785 is Yoast Yoast SEO: Local plugin version <= 14.9.
3
How can I exploit the vulnerability in CVE-2023-28785?
We do not provide information on how to exploit vulnerabilities. It is important to only use this knowledge for defensive purposes.
4
How do I fix CVE-2023-28785?
To fix CVE-2023-28785, update Yoast Yoast SEO: Local plugin to a version beyond 14.9.
5
Where can I find more information about CVE-2023-28785?
You can find more information about CVE-2023-28785 at the following link: [CVE-2023-28785](https://patchstack.com/database/vulnerability/wpseo-local/wordpress-yoast-seo-local-plugin-14-9-cross-site-scripting-xss-vulnerability?_s_id=cve).