The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the `yoast-schema` block attribute in all versions up to, and including, 26.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 1,887,393 live websites that are affected by CVE-2026-1293.
| Product | |
| Category | Search Engine Optimization |
| Vulnerable Domains | 1,887,393 live websites (47% of Yoast SEO install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 310 versions ( 96% of all versions) |
| 520,254 websites | |
| 183,946 websites | |
| 140,775 websites | |
| 98,714 websites | |
| 89,112 websites | |
| 75,095 websites | |
| 63,978 websites | |
| 63,119 websites | |
| 58,688 websites | |
| 39,503 websites |
| .com | 759,310 websites |
| .de | 108,768 websites |
| .it | 72,770 websites |
| .nl | 67,973 websites |
| .org | 67,952 websites |
| .fr | 63,818 websites |
| .co.uk | 60,265 websites |
| .ru | 53,298 websites |
| .pl | 45,324 websites |
| .net | 44,962 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***************.org | *** | ||
| ****************.com | *** | ||
| *******.com | *** | ||
| *********.com | *** | ||
| ***.********.com | *** | ||
| *****.com | *** | ||
| **********.com | *** | ||
| ******.com | *** | ||
| ************.org | *** | ||
| *****.**.uk | *,*** |
FAQ