Showing 5 vulnerabilities on this page for seopress

Signals CISA KEV Ransomware Nuclei
seopress vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WordPress SEOPress plugin <= 8.1.1 - Unauthenticated Broken Access Control vulnerability

Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n/a through <= 8.1.1.

CWE-862Oct 29, 2024
CVSS5.3v3.1EPSS0.345%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SEOPress – On-site SEO <= 8.1.1 - Reflected Cross-Site Scripting

The SEOPress – On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 8.1.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CWE-79Oct 2, 2024
CVSS6.1v3.1EPSS0.426%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SEOPress < 7.9 - Unauthenticated Object Injection

The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present.

CWE-502Jul 9, 20241 related artifact
CVSS9.8v3.1EPSS3.74%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

SEOPress < 7.8 - Contributor+ Stored XSS

The SEOPress WordPress plugin before 7.8 does not sanitise and escape some of its Post settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.

CWE-79Jun 24, 2024
CVSS5.0v3.1EPSS0.337%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SEOPress <= 5.0.0 – 5.0.3 Authenticated Stored Cross-Site Scripting

The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/src/Actions/Api/TitleDescriptionMeta.php file which allows authenticated attackers to inject arbitrary web scripts, in versions 5.0.0 - 5.0.3.

CWE-79Aug 16, 2021
CVSS6.4v3.1EPSS0.648%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX