CVE-2026-53740 – Yoast Duplicate Post through 4.6 Stored Cross-Site Scripting via Scheduled Republish Notice

CVE ID :CVE-2026-53740

Published : June 10, 2026, 8:39 p.m. | 38 minutes ago

Description :Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can schedule a republish copy with a crafted title to execute script when an administrator views the resulting notice.

Severity: 5.4 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more… 

نوشته های مشابه