Record summary

CVE-2021-25118 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Yoast SEO

CVE List16.7 to < 16.7*affected
17.3 to < 17.3affected

Nuclei templates

1
ProjectDiscoveryMEDIUMYoast SEO 16.7-17.2 - Information DisclosureCVSS 5.3

Yoast SEO plugin 16.7 to 17.2 is susceptible to information disclosure, The plugin discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints, which can help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.

Impact

An attacker can exploit this vulnerability to gain sensitive information from the target system.

Remediation

Fixed in version 17.3.

WeaknessesCWE-200
AuthorsDhiyaneshDK
Template tagscve2021cvewpscanwordpresswp-pluginfpdwpyoastvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:yoast:yoast_seo:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3