Executive brief
Yoast SEO Premium is a popular WordPress plugin used to optimize websites for search engines. A security flaw in the plugin's access control settings could allow high-privileged users, such as authors, to perform actions or modify settings they should not have access to. While this requires an existing account with significant permissions, it could lead to unauthorized changes to the website's SEO configuration or operational disruptions.
Technical details
A missing authorization vulnerability (CWE-862) exists in Yoast SEO Premium versions up to and including 26.6. The flaw stems from incorrectly configured access control security levels within the plugin's functional logic. An attacker with high-level privileges (such as an 'Author' or 'Editor' role) can bypass intended restrictions to execute actions or modify settings that should be reserved for higher administrative tiers. The vulnerability is reachable over the network without user interaction, though it requires valid authentication with high-level permissions. The issue is addressed in version 26.7.
Affected products
- Yoast BV Yoast SEO Premium n/a through 26.6
Timeline
- 2025-12-16: other: Reported by researcher ilicfilip
- 2026-01-15: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: NVD publication date