CVE-2026-40722
WordPress Yoast SEO Premium plugin <= 26.6 - Broken Access Control vulnerability
CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th
Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Yoast SEO Premium: from n/a through 26.6.
| CWE | CWE-862 |
| Vendor | yoast bv |
| Product | yoast seo premium |
| Published | Jun 17, 2026 |
| Last Updated | Jun 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for yoast bv yoast seo premium
Be the first to know when new medium vulnerabilities affecting yoast bv yoast seo premium are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
Low
Affected Versions
Yoast BV / Yoast SEO Premium
n/a โค 26.6
References
Credits
ilicfilip | Patchstack Bug Bounty Program