← Vulnerability feed

Vulnerability record · CVE-2021-25118 · published 28 February 2022

CVE-2021-25118: Yoast seo information exposure vulnerability

Yoast · Yoast Seo

The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.

5.3 CVSS 3.1 Medium EPSS 5.6% · top 7.3% CWE-200 · Information exposure
5.3CVSS 3.1 base score, v2 5.0
5.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-25118 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-13478Yoast seo cross-site scripting vulnerabilityThe Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.EPSS 3.3%6.6CVE-2018-19370Yoast seo race condition vulnerabilityA Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0 for WordP…EPSS 3.2%6.4CVE-2021-31779Yoast seo server-side request forgery (ssrf) vulnerabilityThe yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account.EPSS 0.47%6.1CVE-2023-32300Yoast seo cross-site scripting vulnerabilityUnauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.8 versions.EPSS 0.38%5.4CVE-2023-28785Yoast seo cross-site scripting vulnerabilityAuth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.9 versions.EPSS 0.37%5.4CVE-2021-36788Yoast seo cross-site scripting vulnerabilityThe yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.EPSS 0.47%5.4CVE-2021-24153Yoast seo cross-site scripting vulnerabilityA Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which…EPSS 1.1%5.3CVE-2023-28775Yoast seo missing authorization vulnerabilityMissing Authorization vulnerability in Yoast Yoast SEO Premium.This issue affects Yoast SEO Premium: from n/a through 20.4.EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2021-25118), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.