Seopress is a WordPress search-engine optimization plugin that brings web page generation and user-input handling to a widely deployed content management platform, situating it in the attack surface of numerous websites. The plugin's vulnerability profile centers on application-layer weaknesses including cross-site scripting, deserialization flaws, authorization gaps, input-validation issues, and open-redirect conditions that recur across its codebase; a meaningful share of these vulnerabilities reach serious severity and tend to acquire public exploit code. Defenders should prioritize patching this plugin on internet-facing WordPress installations and monitor its release cadence for security updates; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Seopress over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5488CRITICAL The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticate | Jul 9, 2024 | 9.8 | 40 | NO | YES |
CVE-2023-1669HIGH The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection | May 2, 2023 | 7.2 | 30 | NO | NO |
CVE-2024-50456HIGH Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from | Oct 29, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-50455HIGH Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from | Oct 29, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-4900MEDIUM The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perform Open redirect attacks again | Jun 24, 2024 | 6.1 | 19 | NO | NO |
CVE-2021-34641MEDIUM The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/src/Actions/Api/TitleDescriptionMeta.php file which allows aut | Aug 16, 2021 | 5.4 | 19 | NO | NO |
CVE-2024-9225MEDIUM The SEOPress – On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on t | Oct 2, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-1134MEDIUM The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SEO title and description parameters as well as others in all versions up to, a | May 24, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-1168MEDIUM The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's social image URL in all versions up to, and including, 7.9 due to insu | Jun 20, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-2165MEDIUM The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt parameter in all versions up to, and including, 7.5.2.1 due to insuff | Apr 9, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Seopress.
Media articles that mention a CVE ID that affects a product developed by Seopress — matched by CVE ID, not by vendor name.