CVE-2021-25118
The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of…
Does this matter?
Lower severity and a low EPSS score (5.63%). Track it; it rarely justifies an emergency change on its own.
Description
The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 5.63% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- yoast/yoast seo
- Source
- contact@wpscan.com
References
- https://plugins.trac.wordpress.org/changeset/2608691Release Notes, Third Party Advisory
- https://wpscan.com/vulnerability/2c3f9038-632d-40ef-a099-6ea202efb550Exploit, Third Party Advisory
- https://plugins.trac.wordpress.org/changeset/2608691Release Notes, Third Party Advisory
- https://wpscan.com/vulnerability/2c3f9038-632d-40ef-a099-6ea202efb550Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.