The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Slug (post_name) in all versions up to, and including, 28.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires pretty permalinks to be enabled, as the exploit chain depends on get_permalink() embedding the stored percent-encoded post_name in the generated URL.
We have discovered 4,044,506 live websites that are affected by CVE-2026-15425.
| Product | |
| Category | Search Engine Optimization |
| Vulnerable Domains | 4,044,506 live websites (100% of Yoast SEO install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 322 versions ( 100% of all versions) |
| 1,359,250 websites | |
| 401,950 websites | |
| 278,396 websites | |
| 201,611 websites | |
| 185,265 websites | |
| 168,549 websites | |
| 119,107 websites | |
| 93,980 websites | |
| 91,525 websites | |
| 87,527 websites |
| .com | 1,722,033 websites |
| .de | 252,618 websites |
| .org | 178,921 websites |
| .nl | 171,208 websites |
| .co.uk | 136,007 websites |
| .fr | 133,681 websites |
| .it | 126,610 websites |
| .net | 94,365 websites |
| .ru | 74,243 websites |
| .com.au | 73,351 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***************.org | *** | ||
| ******.net | *** | ||
| ****************.com | *** | ||
| ******.org | *** | ||
| *********.de | *** | ||
| ****.*****.com | *** | ||
| *******.com | *** | ||
| *****.com | *** | ||
| *********.com | *** | ||
| ******.org | *** |
FAQ