CVE-2026-10821
Last modified
CVE-2026-10821 is a medium-severity vulnerability rated 6.6/10 on the CVSS scale. The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before writing them to the site's Apache configuration file when the file-based redirect mode is enabled, and the redirect-creation endpoint is reachable by users with only Author-level access. This allows such users to inject arbitrary newline-delimited Apache directives into the root .htaccess file. EPSS estimates a 0.51% chance of exploitation in the next 30 days.
Description
The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before writing them to the site's Apache configuration file when the file-based redirect mode is enabled, and the redirect-creation endpoint is reachable by users with only Author-level access. This allows such users to inject arbitrary newline-delimited Apache directives into the root .htaccess file. On Apache servers that honour PHP directives, the injection can be chained with the user's own media upload (a polyglot image carrying a PHP payload) and an auto_prepend_file directive to achieve Remote Code Execution.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | Yoast SEO Premium | < 27.6.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-10821?
How severe is CVE-2026-10821?
How do I fix CVE-2026-10821?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10816Arbitrary File Read (Unauthenticated) in NetScaler ADC and N…7.5
- CVE-2026-10817Insufficient input validation leading to memory overread in …7.5
- CVE-2026-10818The WPForms Pro plugin for WordPress is vulnerable to Arbitr…8.1
- CVE-2026-10819Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 1…6.5
- CVE-2026-1082The TITLE ANIMATOR plugin for WordPress is vulnerable to Cro…4.3
- CVE-2026-10820The Paid Membership Plugin, Ecommerce, User Registration For…8.1
- CVE-2026-10822If BIND encounters a particular invalid data structure in a …6.5
- CVE-2026-10823The YMC Filter WordPress plugin before 3.11.3 does not prope…7.5
- CVE-2026-10824The Masteriyo LMS WordPress plugin before 2.2.1 does not pe…6.5
- CVE-2026-10825A denial-of-service vulnerability exists in the WebSocket AP…7.1
- CVE-2026-10827The Spectra Legacy WordPress plugin before 2.20.0 does not …3.5
- CVE-2026-10828A format string vulnerability has been found in the "alias" …6.9
Are you affected by CVE-2026-10821?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
