The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the `yoast-schema` block attribute in all versions up to, and including, 26.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 2,502,255 live websites that are affected by CVE-2026-1293.
| Product | |
| Category | Search Engine Optimization |
| Vulnerable Domains | 2,502,255 live websites (61% of Yoast SEO install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 391 versions ( 98% of all versions) |
| 740,339 websites | |
| 246,079 websites | |
| 180,133 websites | |
| 123,473 websites | |
| 123,427 websites | |
| 103,400 websites | |
| 78,841 websites | |
| 75,657 websites | |
| 69,706 websites | |
| 52,998 websites |
| .com | 1,031,487 websites |
| .de | 145,796 websites |
| .org | 95,504 websites |
| .nl | 95,397 websites |
| .it | 91,374 websites |
| .co.uk | 83,581 websites |
| .fr | 83,022 websites |
| .ru | 64,091 websites |
| .net | 59,901 websites |
| .pl | 53,774 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***************.org | *** | ||
| ****************.com | *** | ||
| ********.com | *** | ||
| *******.com | *** | ||
| *********.com | *** | ||
| *********.com | *** | ||
| ***.********.com | *** | ||
| **********.com | *** | ||
| *********.com | *** | ||
| ******.com | *** |
FAQ