CVE-2024-4041

MEDIUM

Yoast SEO <= 22.5 - Unauthenticated Reflected Cross-Site Scripting via URL Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-4041. PoCs published by RandomRobbieBF.

AI-analyzed exploit summary The repository provides a functional proof-of-concept for CVE-2024-4041, demonstrating a reflected XSS vulnerability in Yoast SEO plugin for WordPress. The PoC involves crafting a malicious URL that, when interacted with, executes arbitrary JavaScript in the context of the victim's browser.

Description

The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 22.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Exploits (1)

github WORKING POC
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2024-4041

The repository provides a functional proof-of-concept for CVE-2024-4041, demonstrating a reflected XSS vulnerability in Yoast SEO plugin for WordPress. The PoC involves crafting a malicious URL that, when interacted with, executes arbitrary JavaScript in the context of the victim's browser.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Yoast SEO plugin for WordPress <= 22.5
No auth needed
Prerequisites: Victim interaction (e.g., clicking a crafted link) · Yoast SEO plugin version <= 22.5 installed on target WordPress site
MITRE ATT&CK
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Scores

CVSS v3 6.1
EPSS 0.0083
EPSS Percentile 52.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
yoast/Yoast SEO < 22.5
yoast/Yoast SEO – Advanced SEO with real-time guidance and built-in AI < 22.5
Published May 14, 2024
Tracked Since Feb 18, 2026