CVE-2026-53740

Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can schedule a republish copy with a crafted title to execute script when an administrator views the resulting notice.
Configurations

No configuration.

History

23 Jul 2026, 09:10

Type Values Removed Values Added
Summary
  • (es) Yoast Duplicate Post hasta la 4.6 inserta un título de entrada y un enlace permanente sin escapar en el aviso de republicación programada del Editor Clásico. Los atacantes pueden programar una copia de republicación con un título manipulado para ejecutar scripts cuando un administrador ve el aviso resultante.

10 Jun 2026, 22:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-10 22:17

Updated : 2026-07-23 09:10


NVD link : CVE-2026-53740

Mitre link : CVE-2026-53740

CVE.ORG link : CVE-2026-53740


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')