nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-34641 CVE-2021-34641
MEDIUM
SEOPress <= 5.0.0 – 5.0.3 Authenticated Stored Cross-Site Scripting
Record summary
CVE-2021-34641 has a selected CVSS score of 6.4 (medium).
Description
The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/src/Actions/Api/TitleDescriptionMeta.php file which allows authenticated attackers to inject arbitrary web scripts, in versions 5.0.0 - 5.0.3.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 22, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 5, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SEOPressBrowse SEOPress / SEOPress | CVE List, VulnCheck | 5.0.0 | affected |
| 5.0.1 | affected | ||
| 5.0.2 | affected | ||
| 5.0.3 | affected |
References
3plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/wp-seopress/tags/5.0.4/src/Actions/Api/TitleDescriptionMeta.php wordfence.com
https://www.wordfence.com/blog/2021/08/xss-vulnerability-patched-in-seopress-affects-100000-sites