Medium severity5.4NVD Advisory· Published Jun 10, 2026· Updated Jun 11, 2026
CVE-2026-53740
CVE-2026-53740
Description
Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can schedule a republish copy with a crafted title to execute script when an administrator views the resulting notice.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=4.6
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.