Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before writing them to the site's Apache configuration file when the file-based redirect mode is enabled, and the redirect-creation endpoint is reachable by users with only Author-level access. This allows such users to inject arbitrary newline-delimited Apache directives into the root .htaccess file. On Apache servers that honour PHP directives, the injection can be chained with the user's own media upload (a polyglot image carrying a PHP payload) and an auto_prepend_file directive to achieve Remote Code Execution. | |
| Title | Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection to RCE | |
| Weaknesses | CWE-74 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-02T14:57:38.690Z
Reserved: 2026-06-04T07:41:54.109Z
Link: CVE-2026-10821
Updated: 2026-09-02T14:44:37.234Z
Status : Received
Published: 2026-09-02T15:17:37.267
Modified: 2026-09-02T15:17:37.267
Link: CVE-2026-10821
No data.
OpenCVE Enrichment
No data.
-
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')