CVE-2021-25118

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
28/02/2022
Last modified:
27/10/2022

Description

The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:yoast:yoast_seo:*:*:*:*:*:wordpress:*:* 16.7 (including) 17.3 (excluding)