CVE-2025-14481: Yoast SEO <= 26.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'post_id' Parameter
The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all versions up to, and including, 26.5. This is due to insufficient authorization checks in the Meta Search REST API endpoint that fail to verify post ownership. This makes it possible for authenticated attackers, with Contributor-level access and above, to read sensitive SEO metadata from any post on the site via the 'postid' parameter, including posts owned by other users, private posts, and draft posts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Yoast SEO pluginto a version that resolves this vulnerability.Fixed in 26.5
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14481?
CVE-2025-14481 has a medium severity score of 4.3.
How does CVE-2025-14481 affect Yoast SEO users?
CVE-2025-14481 allows authenticated users to access sensitive information due to insecure direct object reference.
How do I fix CVE-2025-14481?
To fix CVE-2025-14481, update your Yoast SEO plugin to version 26.6 or later.
What kind of vulnerability is CVE-2025-14481?
CVE-2025-14481 is classified as an Insecure Direct Object Reference vulnerability.
What versions of Yoast SEO are affected by CVE-2025-14481?
CVE-2025-14481 affects all versions of Yoast SEO up to and including version 26.5.