seopress Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with seopress products.
Products
- seopress5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-50454MEDIUM | WordPress SEOPress plugin <= 8.1.1 - Unauthenticated Broken Access Control vulnerabilityMissing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n/a through <= 8.1.1. CWE-862Oct 29, 2024 | CVSS5.3v3.1 | EPSS0.345% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-9225MEDIUM | SEOPress – On-site SEO <= 8.1.1 - Reflected Cross-Site ScriptingThe SEOPress – On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 8.1.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CWE-79Oct 2, 2024 | CVSS6.1v3.1 | EPSS0.426% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-5488CRITICAL | SEOPress < 7.9 - Unauthenticated Object InjectionThe SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present. | CVSS9.8v3.1 | EPSS3.74% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-4899MEDIUM | SEOPress < 7.8 - Contributor+ Stored XSSThe SEOPress WordPress plugin before 7.8 does not sanitise and escape some of its Post settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks. CWE-79Jun 24, 2024 | CVSS5.0v3.1 | EPSS0.337% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-34641MEDIUM | SEOPress <= 5.0.0 – 5.0.3 Authenticated Stored Cross-Site ScriptingThe SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/src/Actions/Api/TitleDescriptionMeta.php file which allows authenticated attackers to inject arbitrary web scripts, in versions 5.0.0 - 5.0.3. CWE-79Aug 16, 2021 | CVSS6.4v3.1 | EPSS0.648% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |