CVE-2026-1293

Yoast SEO <= 26.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'yoast-schema' Block Attribute

The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the `yoast-schema` block attribute in all versions up to, and including, 26.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 1,887,393 live websites that are affected by CVE-2026-1293.

Run a Free Instant Scan




Affected Software

Product  Yoast SEO
Category Search Engine Optimization
Vulnerable Domains1,887,393 live websites (47% of Yoast SEO install base)
Vulnerable Versions
  • from 0 through 26.8
Vulnerable Versions Count310 versions ( 96% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Feb 6, 2026
  • Updated - Apr 8, 2026

Credits

  • suyoung kim (finder)

Website Distribution by Country

Number of websites using CVE-2026-1293
United States520,254 websites



Germany183,946 websites
France140,775 websites
Italy98,714 websites
GB89,112 websites
Netherlands75,095 websites
Spain63,978 websites
Russia63,119 websites
Poland58,688 websites
Canada39,503 websites

Website Distribution by TLD

Number of websites using CVE-2026-1293
.com759,310 websites
.de108,768 websites
.it72,770 websites
.nl67,973 websites
.org67,952 websites
.fr63,818 websites
.co.uk60,265 websites
.ru53,298 websites
.pl45,324 websites
.net44,962 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-1293

Top websites that are affected by CVE-2026-1293. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.org United States***
****************.com United States***
*******.com United States***
*********.com United States***
***.********.com United States***
*****.com United States***
**********.com United States***
******.com United States***
************.org United States***
*****.**.uk GB*,***
See full domain list

FAQ

CVE-2026-1293 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Yoast SEO
A total of 1,887,393 websites have been identified as vulnerable to CVE-2026-1293, based on global website indexing conducted by WebTechSurvey.
The Yoast SEO is affected by the CVE-2026-1293 vulnerability.
Yoast SEO versions up to and including 26.8 are vulnerable to CVE-2026-1293.