Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Seopress

First CVE: Aug 16, 2021Active for: 5 yearsTotal CVEs: 12
32.0
VTI Score
Medium

Seopress is a WordPress search-engine optimization plugin that brings web page generation and user-input handling to a widely deployed content management platform, situating it in the attack surface of numerous websites. The plugin's vulnerability profile centers on application-layer weaknesses including cross-site scripting, deserialization flaws, authorization gaps, input-validation issues, and open-redirect conditions that recur across its codebase; a meaningful share of these vulnerabilities reach serious severity and tend to acquire public exploit code. Defenders should prioritize patching this plugin on internet-facing WordPress installations and monitor its release cadence for security updates; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
4.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Seopress over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 16, 2021
4 years ago
Most Recent CVE
Oct 29, 2024
634 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-5488CRITICAL
The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticate
Jul 9, 20249.840NOYES
CVE-2023-1669HIGH
The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection
May 2, 20237.230NONO
CVE-2024-50456HIGH
Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from
Oct 29, 20248.824NONO
CVE-2024-50455HIGH
Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from
Oct 29, 20248.824NONO
CVE-2024-4900MEDIUM
The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perform Open redirect attacks again
Jun 24, 20246.119NONO
CVE-2021-34641MEDIUM
The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/src/Actions/Api/TitleDescriptionMeta.php file which allows aut
Aug 16, 20215.419NONO
CVE-2024-9225MEDIUM
The SEOPress – On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on t
Oct 2, 20246.118NONO
CVE-2024-1134MEDIUM
The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SEO title and description parameters as well as others in all versions up to, a
May 24, 20245.417NONO
CVE-2024-1168MEDIUM
The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's social image URL in all versions up to, and including, 7.9 due to insu
Jun 20, 20245.416NONO
CVE-2024-2165MEDIUM
The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt parameter in all versions up to, and including, 7.5.2.1 due to insuff
Apr 9, 20245.416NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
67%
25%
8%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (91.7%)
High1 (8.3%)
Unknown0 (0.0%)
User Interaction
None4 (33.3%)
Unknown0 (0.0%)
Required8 (66.7%)
Privileges Required
Low6 (50.0%)
High2 (16.7%)
None4 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
8.3% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Seopress.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Seopress — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Seopress's Products

View all 3 CNAs →

Top CWEs