Yoast Vulnerabilities and Affected Products
Vulnerabilities associated with Yoast Duplicate Post.
Products
Clear product- Yoast SEO – Advanced SEO with real-time guidance and built-in AI6 vulnerabilities
- Yoast Duplicate Post3 vulnerabilities
- Yoast SEO: Local2 vulnerabilities
- Duplicate-Post1 vulnerability
- Yoast Local Premium1 vulnerability
- Yoast SEO Premium1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-53740MEDIUM | Yoast Duplicate Post through 4.6 Stored Cross-Site Scripting via Scheduled Republish NoticeYoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can schedule a republish copy with a crafted title to execute script when an administrator views the resulting notice. CWE-79Jun 10, 2026 | CVSS5.1v4.0 | EPSS0.141% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-53739MEDIUM | Yoast Duplicate Post through 4.6 Cross-Site Request Forgery via duplicate_post_dismiss_noticeYoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicate_post_dismiss_notice handler, which verifies no nonce or capability. Attackers can trick any authenticated user into sending a request that sets the duplicate_post_show_notice site option, suppressing admin notices network-wide. CWE-352Jun 10, 2026 | CVSS5.1v4.0 | EPSS0.104% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-1217MEDIUM | Yoast Duplicate Post <= 4.5 - Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and OverwriteThe Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate any post on the site including private, draft, and trashed posts they shouldn't have access to. Additionally, attackers with Author-level access and ab… CWE-862Mar 18, 2026 | CVSS5.4v3.1 | EPSS0.171% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |