6.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Description
The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the `yoast-schema` block attribute in all versions up to, and including, 26.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Basic Information
ID
CVE-2026-1293
Source
Wordfence
Published
Feb 6, 2026 at 11:21
Affected Product
Vendor
yoast
Product
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
Version
*
Affected Versions
yoast Yoast SEO – Advanced SEO with real-time guidance and built-in AI *
CWE Classification
References
- www.wordfence.com /threat-intel/vulnerabilities/id/8b2e7c2d-ed2f-439b-9cee-f2e5d46121b6
- plugins.trac.wordpress.org /browser/wordpress-seo/tags/26.8/src/presenters/schema-presenter.php
- plugins.trac.wordpress.org /browser/wordpress-seo/tags/26.8/inc/class-wpseo-utils.php
- plugins.trac.wordpress.org /browser/wordpress-seo/tags/26.8/src/generators/schema-generator.php