CVE-2023-40680: WordPress Yoast SEO Plugin <= 21.0 is vulnerable to Cross Site Scripting (XSS)
Published Nov 30, 2023
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Yoast Yoast SEO allows Stored XSS.This issue affects Yoast SEO: from n/a through 21.0.
Affected Software
1 affected component
Yoast Yoast SEO WordPress<=21.0
Remediation
Information
Update to 21.1 or a higher version.
Event History
Nov 30, 2023
CVE Published
via MITRE·12:21 PM
Data Sourced
via MITRE·12:21 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-40680.
2
What is the title of the vulnerability?
The title of the vulnerability is 'WordPress Yoast SEO Plugin <= 21.0 is vulnerable to Cross Site Scripting (XSS)'.
3
What is the severity of CVE-2023-40680?
The severity of CVE-2023-40680 is medium with a severity value of 5.9.
4
What is the affected software?
The affected software is Yoast SEO plugin version up to and including 21.0 on WordPress.
5
How do I fix CVE-2023-40680?
To fix CVE-2023-40680, update the Yoast SEO plugin to a version higher than 21.0.