Junglewise Threat Intelligence

CVE-2026-53740: Yoast Duplicate Post stored XSS in Classic Editor republish notice

CVE-2026-53740 · Severity: medium · CVSS 5.4 · Published 2026-06-10

Technologies: Yoast Duplicate Post. Vendors: Yoast.

Executive brief

Yoast Duplicate Post is a popular WordPress plugin used to clone and manage website content. A security flaw allows an attacker with basic posting privileges to insert malicious scripts into the titles of scheduled posts. When a site administrator later views the republishing notice in the Classic Editor, the script executes, potentially allowing the attacker to perform unauthorized actions or compromise the administrator's session.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Yoast Duplicate Post through version 4.6. The root cause is the failure to escape the post title and permalink when generating the scheduled republish notice within the WordPress Classic Editor interface. An attacker with at least contributor-level permissions (PR:L) can create a 'Rewrite & Republish' copy of a post with a malicious payload in the title. When an administrator or editor views the resulting notice, the script executes in their browser context. This can lead to session hijacking or unauthorized administrative actions. While version 4.6 included some security enhancements for republishing, the specific XSS in the Classic Editor notice was reported as persisting through that version.

Affected products

  • Yoast Yoast Duplicate Post <= 4.6

Timeline

  • 2026-06-10: advisory: Advisory published by VulnCheck and NVD

References

Related threats