PT-2019-13358 · Yoast · Yoast Seo Plugin

Published

2019-07-09

·

Updated

2023-02-24

·

CVE-2019-13478

CVSS v3.1

9.9

Critical

VectorAC:L/AV:N/A:L/C:H/I:H/PR:L/S:C/UI:N
Name of the Vulnerable Software and Affected Versions Yoast SEO plugin versions prior to 11.6-RC5
Description The issue concerns the improper restriction of unfiltered HTML in term descriptions, which could lead to potential security risks.
Recommendations For versions prior to 11.6-RC5, update to version 11.6-RC5 or later to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-13478

Affected Products

Yoast Seo Plugin