Discoverer: Elias Dimopoulos Linkedin: https://gr.linkedin.com/in/dimopouloselias Vulnerability: Reflected XSS Affected plugin: Yoast SEO plugin < 5.8.0 Active installations: 5+ million URL: https://wordpress.org/plugins/wordpress-seo/#developers Assigned CVE: CVE-2017-16842 ----------------------------------------------------------- Thanks Yoast for their immediate response. ----------------------------------------------------------- The vulnerability lies in the "tab" parameter and can cause reflected XSS vulnerability. The vulnerability can be exploited against an administrator by using the following url: http://victim/wp-admin/admin.php?page=wpseo_search_console&tab=settings'>