CVE-2025-11241: Yoast SEO Premium 25.7-25.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 25.7 to 25.9 due to a flawed regex used to remove an attribute in post content, which can be abused to inject arbitrary HTML attributes, including JavaScript event handlers. This vulnerability allows a user with Contributor access or higher to create a post containing a malicious JavaScript payload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11241?
CVE-2025-11241 is considered a medium severity vulnerability that allows stored cross-site scripting in the Yoast SEO Premium plugin.
How do I fix CVE-2025-11241?
To fix CVE-2025-11241, update the Yoast SEO Premium plugin to version 26.0 or later.
What versions are affected by CVE-2025-11241?
CVE-2025-11241 affects Yoast SEO Premium versions 25.7 to 25.9.
What type of vulnerability is CVE-2025-11241?
CVE-2025-11241 is a stored cross-site scripting vulnerability due to improper handling of post content.
Who is the vendor for the CVE-2025-11241 vulnerability?
The vendor for the CVE-2025-11241 vulnerability is Yoast.