cleantalk
Vulnerabilities and Security Researches

Yoast SEO, CVE-2021-25118

CVE, Research URL

CVE-2021-25118

Application

Yoast SEO

Published on
Feb 28, 2022
Research Description
The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.
Affected versions
Min -, max 17.3.
Status
vulnerable