{"id":"CVE-2021-25118","details":"The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.","modified":"2026-09-08T08:06:32.672563Z","published":"2022-02-28T09:15:08.720Z","references":[{"type":"ADVISORY","url":"https://plugins.trac.wordpress.org/changeset/2608691"},{"type":"EVIDENCE","url":"https://wpscan.com/vulnerability/2c3f9038-632d-40ef-a099-6ea202efb550"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/yoast/wordpress-seo","events":[{"introduced":"cc6a50cb82e261fed9edd961e9937a96fb0c1f0c"},{"fixed":"71353e912a3ed264ff39e0bc3929bac8d8a31edc"}],"database_specific":{"cpe":"cpe:2.3:a:yoast:yoast_seo:*:*:*:*:*:wordpress:*:*","extracted_events":[{"introduced":"16.7"},{"fixed":"17.3"}],"source":"CPE_RANGE"}}],"versions":["17.2.1","17.2","17.1","17.0","16.9","16.8","16.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-25118.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}