Home/Product/seopress
Product

seopress

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-50456
<= 8.2
Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control
5.4MEDIUM
CVE-2024-50455
< 8.2
Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control
4.3MEDIUM
CVE-2024-9225
< 8.2
The SEOPress - On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg &
6.1MEDIUM
CVE-2024-5488
< 7.9
The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Objec
9.8CRITICAL
CVE-2024-4900
< 7.8
The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and
6.1MEDIUM
CVE-2024-4899
< 7.8
The SEOPress WordPress plugin before 7.8 does not sanitise and escape some of its Post settings, which could allow high privilege
5.0MEDIUM
CVE-2024-1168
<= 7.9
The SEOPress - On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's social image URL in
6.4MEDIUM
CVE-2024-1134
< 7.6
The SEOPress - On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SEO title and description par
6.4MEDIUM
CVE-2024-2165
< 7.6
The SEOPress - On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt parameter in all ve
6.4MEDIUM
CVE-2023-6290
< 7.3
The SEOPress WordPress plugin before 7.3 does not sanitise and escape some of its settings, which could allow high privilege users
4.8MEDIUM
CVE-2023-1669
< 6.5.0.3
The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege u
7.2HIGH
CVE-2021-34641
>= 5.0.0 and < 5.0.4
The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/src/Actions/
6.4MEDIUM
threatengine.sh