{"error":0,"message":null,"data":{"name":"SEOPress &#8211; AI SEO Plugin &amp; On-site SEO","plugin":"wp-seopress","link":"https:\/\/wordpress.org\/plugins\/wp-seopress\/","latest":"1789129380","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"3884c49b81745ac292c6e658f7003ba511abe09cef598a2e84ff600c25024805","name":"SEOPress &#8211; AI SEO Plugin &amp; On-site SEO [wp-seopress] >= 5.0.0 - <= 5.0.3","description":null,"operator":{"min_version":"5.0.0","min_operator":"ge","max_version":"5.0.3","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-34641","name":"CVE-2021-34641","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-34641","description":"[en] The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~\/src\/Actions\/Api\/TitleDescriptionMeta.php file which allows authenticated attackers to inject arbitrary web scripts, in versions 5.0.0 - 5.0.3.","date":"2021-08-16"},{"id":"12421c9910c42ff6ae4bb881c0055fea0789114c","name":"WordPress SEOPress, on-site SEO plugin 5.0.0 \u2013 5.0.3 - Stored Cross-Site Scripting (XSS) vulnerability via REST-API","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-seopress\/vulnerability\/wordpress-seopress-on-site-seo-plugin-5-0-0-5-0-3-stored-cross-site-scripting-xss-vulnerability-via-rest-api","description":"Stored Cross-Site Scripting (XSS) vulnerability via REST-API discovered by Chloe Chamberland (WordFence) in WordPress SEOPress, on-site SEO plugin (versions 5.0.0 \u2013 5.0.3).","date":"2021-08-16"},{"id":"3dc1c409272471d48c599937c42f40cff5c08415","name":"SEOPress 5.0.0 - 5.0.3 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-seopress\/seopress-500-503-stored-cross-site-scripting","description":"The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~\/src\/Actions\/Api\/TitleDescriptionMeta.php file which allows authenticated attackers to inject arbitrary web scripts, in versions 5.0.0 - 5.0.3.","date":"2021-08-16"},{"id":"b88613a6-7321-409f-bba3-36450fb17724","name":"SEOPress 5.0.0 &ndash; 5.0.3 - Authenticated Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/b88613a6-7321-409f-bba3-36450fb17724","description":"The plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~\/src\/Actions\/Api\/TitleDescriptionMeta.php file which allows authenticated attackers to inject arbitrary web scripts.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"bb7f9091799f854c717214fb2ad27a88519ae06de2b71c558734527870c22337","name":"SEOPress &#8211; AI SEO Plugin &amp; On-site SEO [wp-seopress] < 6.5.0.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5.0.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"cb8205008c00b389fe9d4ad377f0d6849d949ba2","name":"SEOPress <= 6.5.0.2 - Authenticated (Administrator+) PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-seopress\/seopress-6502-authenticated-administrator-php-object-injection","description":"The SEOPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.5.0.2 via deserialization of untrusted input of the $redirect_value['sources'] value triggered to an import with the seopress_import_rk_redirections function. This allows authenticated attackers, with administrator-level privileges, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2023-04-05"},{"id":"CVE-2023-1669","name":"CVE-2023-1669","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1669","description":"[en] The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.","date":"2023-05-02"},{"id":"fb8791f5-2879-431e-9afc-06d5839e4b9d","name":"SEOPress &lt; 6.5.0.3 - Admin+ PHP Object Injection","link":"https:\/\/wpscan.com\/vulnerability\/fb8791f5-2879-431e-9afc-06d5839e4b9d","description":"The plugin unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"4e7b282ec8a2b94551cb85749a992b5370c1999cb5218d85558bf9c94d1a385a","name":"SEOPress &#8211; AI SEO Plugin &amp; On-site SEO [wp-seopress] < 6.5.0.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5.0.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"135ea454677063d654cb1349f23f35188cf16f32","name":"WordPress  SEOPress Plugin  <= 6.5.0.2 is vulnerable to PHP Object Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-seopress\/vulnerability\/wordpress-seopress-plugin-6-5-0-2-authenticated-administrator-php-object-injection-vulnerability","description":"Update the WordPress SEOPress plugin to the latest available version (at least 6.5.0.3).\nUnknown discovered and reported this PHP Object Injection vulnerability in WordPress SEOPress Plugin. This could allow a malicious actor to execute code injection, SQL injection, path traversal, denial of service, and more if a proper POP chain is present. This vulnerability has been fixed in version 6.5.0.3.","date":"2023-04-06"}],"impact":[]},{"uuid":"dc0b497c93de4846f8ef55e479c79d56cd7a4fc111f5552cf7440bac22b58a9d","name":"SEOPress &#8211; AI SEO Plugin &amp; On-site SEO [wp-seopress] < 7.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6290","name":"CVE-2023-6290","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6290","description":"[en] The SEOPress WordPress plugin before 7.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed","date":"2024-01-22"},{"id":"7f4f16b88467f4360184c8b75f06536004a738b1","name":"SEOPress \u2013 On-site SEO <= 7.2 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-seopress\/seopress-on-site-seo-72-authenticated-admin-stored-cross-site-scripting","description":"The SEOPress \u2013 On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2023-12-26"},{"id":"78a13958-cd12-4ea8-b326-1e3184da970b","name":"WP SEO Press &lt; 7.3 - Admin+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/78a13958-cd12-4ea8-b326-1e3184da970b","description":"The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"098e8a96e0ccc8fb37cf2937be46cd136142ac2163a1ea7f58df45374f027028","name":"SEOPress &#8211; AI SEO Plugin &amp; On-site SEO [wp-seopress] < 7.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2165","name":"CVE-2024-2165","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2165","description":"[en] The SEOPress \u2013 On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt parameter in all versions up to, and including, 7.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-09"},{"id":"109767bad66c92b8da957b6e21698a1a501c5dfe","name":"SEOPress \u2013 On-site SEO <= 7.5.2.1 - Authenticated (Author+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-seopress\/seopress-on-site-seo-7521-authenticated-author-stored-cross-site-scripting","description":"The SEOPress \u2013 On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt parameter in all versions up to, and including, 7.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-22"},{"id":"25537f5bf4f6b2c3d1b408c246d6665be7d80104","name":"WordPress  SEOPress Plugin    <= 7.5.2.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-seopress\/vulnerability\/wordpress-seopress-plugin-7-5-2-1-authenticated-author-stored-cross-site-scripting-vulnerability","description":"Update the WordPress SEOPress plugin to the latest available version (at least 7.6).\nNg\u00f4 Thi\u00ean An (ancorn_) - VNPT-VCI ST discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress SEOPress Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 7.6.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"21d89532-2f2c-4f2d-bb6f-dfcd7f4fc82b","name":"SEOPress &ndash; On-site SEO &lt; 7.6 - Author+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/21d89532-2f2c-4f2d-bb6f-dfcd7f4fc82b","description":"The SEOPress &ndash; On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt parameter due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-20","name":"Improper Input Validation","description":"The product receives input or data, but it does\n        not validate or incorrectly validates that the input has the\n        properties that are required to process the data safely and\n        correctly."},{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"5e418973146cbe12921e649206fc260b6242c3f81e396c07e729c6530af6ca9e","name":"SEOPress &#8211; AI SEO Plugin &amp; On-site SEO [wp-seopress] < 7.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-34383","name":"CVE-2024-34383","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-34383","description":"[en] Authorization Bypass Through User-Controlled Key vulnerability in The SEO Guys at SEOPress SEOPress.This issue affects SEOPress: from n\/a through 7.7.1.","date":"2024-05-06"},{"id":"6a70305413aad0d86b5aea8ea729aa011bf56d0f","name":"WordPress SEOPress Plugin <= 7.6.1 is vulnerable to Insecure Direct Object References (IDOR)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-seopress\/vulnerability\/wordpress-seopress-plugin-7-6-1-sensitive-data-exposure-vulnerability","description":"<p>WordPress SEOPress Plugin <= 7.6.1 is vulnerable to Insecure Direct Object References (IDOR)<\/p><p>Software: SEOPress<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wp-seopress\/#developers<\/p><p>Affected Version <= 7.6.1<\/p><p>Fixed in version 7.7 <\/p>","date":"2024-05-03"},{"id":"4145c648533efbbbbe015b1c5df07232cdcec032","name":"SEOPress <= 7.6.1 - Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-seopress\/seopress-761-information-exposure","description":"The SEOPress \u2013 On-site SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.6.1. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.","date":"2024-05-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"dd8fe5b3b3c1cc509d064914946efa33364d997c67c8fc61250eebcda338fe81","name":"SEOPress &#8211; AI SEO Plugin &amp; On-site SEO [wp-seopress] < 7.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1134","name":"CVE-2024-1134","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1134","description":"[en] The SEOPress \u2013 On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SEO title and description parameters as well as others in all versions up to, and including, 7.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-24"},{"id":"b4b366b80bbb55836e39e9261ba57f03d34d1d21","name":"SEOPress \u2013 On-site SEO <= 7.5.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-seopress\/seopress-on-site-seo-7521-authenticated-contributor-stored-cross-site-scripting","description":"The SEOPress \u2013 On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SEO title and description parameters as well as others in all versions up to, and including, 7.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-23"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"03cf98af7339edd0514ba469c3c9ae76f3cc202980681dd1aca0939cad6076bc","name":"SEOPress &#8211; AI SEO Plugin &amp; On-site SEO [wp-seopress] < 7.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4899","name":"CVE-2024-4899","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4899","description":"[en] The SEOPress  WordPress plugin before 7.8 does not sanitise and escape some of its Post settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.","date":"2024-06-24"},{"id":"813347527b386f696b5708b3901741bf6b5d735d","name":"SEOPress <= 7.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-seopress\/seopress-772-authenticated-contributor-stored-cross-site-scripting","description":"The SEOPress \u2013 On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SEO Title field parameter in all versions up to, and including, 7.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-03"},{"id":"225aeea62a20168c48b2834169a13084d57cefc1","name":"WordPress SEOPress Plugin < 7.8 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-seopress\/vulnerability\/wordpress-seopress-plugin-7-8-contributor-stored-xss-vulnerability","description":"<p>WordPress SEOPress Plugin < 7.8 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: SEOPress<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wp-seopress\/#developers<\/p><p>Affected Version < 7.8<\/p><p>Fixed in version 7.8 <\/p>","date":"2024-06-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:U\/C:L\/I:L\/A:L","av":"n","ac":"h","pr":"n","ui":"r","s":"u","c":"l","i":"l","a":"l","score":"5.0","severity":"m","exploitable":"1.6","impact":"3.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:U\/C:L\/I:L\/A:L","score":"5.0","severity":"medium","av":"network","ac":"high","pr":"none","ui":"required","s":"unchanged","c":"low","i":"low","a":"low","exploitable":"1.6","impact":"3.4"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3fd9e506cc361361bf2366b33138edcad31baa0b69b4d7ac0a94b6775fc5ef24","name":"SEOPress &#8211; AI SEO Plugin &amp; On-site SEO [wp-seopress] < 7.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4900","name":"CVE-2024-4900","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4900","description":"[en] The SEOPress  WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perform Open redirect attacks against any user viewing a malicious post","date":"2024-06-24"},{"id":"84dba08bf0f05798104d3bb4650810025293ee95","name":"SEOPress <= 7.7.2 - Authenticated (Contributor+) Open Redirect","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-seopress\/seopress-772-authenticated-contributor-open-redirect","description":"The SEOPress \u2013 On-site SEO plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 7.7.2. This is due to insufficient validation on the social post settings. This makes it possible for an authenticated attacker, with contributor-level access and above, to redirect users to potentially malicious sites if they can successfully trick them into performing an action.","date":"2024-06-03"},{"id":"88efbc871258d41f5c83187c5c74f48efedee6f8","name":"WordPress SEOPress Plugin < 7.8 is vulnerable to Open Redirection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-seopress\/vulnerability\/wordpress-seopress-plugin-7-8-contributor-open-redirect-vulnerability","description":"<p>WordPress SEOPress Plugin < 7.8 is vulnerable to Open Redirection<\/p><p>Software: SEOPress<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wp-seopress\/#developers<\/p><p>Affected Version < 7.8<\/p><p>Fixed in version 7.8 <\/p>","date":"2024-06-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-601","name":"URL Redirection to Untrusted Site ('Open Redirect')","description":"The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"706d89d494851bc45eba802ea880f700a44288660b02e198e7ab35ec19f10023","name":"SEOPress &#8211; AI SEO Plugin &amp; On-site SEO [wp-seopress] < 7.9.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.9.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1168","name":"CVE-2024-1168","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1168","description":"[en] The SEOPress \u2013 On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's social image URL in all versions up to, and including, 7.9 due to insufficient input sanitization and output escaping on user supplied image URLs. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-20"},{"id":"e6df2fa7613440122933d713ab4992dcebfc48e1","name":"SEOPress \u2013 On-site SEO <= 7.9 - Authenticated(Contributor+) Stored Cross-Site Scripting via Social Image URL","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-seopress\/seopress-on-site-seo-79-authenticatedcontributor-stored-cross-site-scripting-via-social-image-url","description":"The SEOPress \u2013 On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's social image URL in all versions up to, and including, 7.9 due to insufficient input sanitization and output escaping on user supplied image URLs. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-19"},{"id":"c9adccd5fdbf62dbec24dec3de58ea5d661ca504","name":"WordPress SEOPress Plugin <= 7.9 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-seopress\/vulnerability\/wordpress-seopress-plugin-7-9-authenticated-stored-cross-site-scripting-vulnerability","description":"<p>WordPress SEOPress Plugin <= 7.9 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: SEOPress<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wp-seopress\/#developers<\/p><p>Affected Version <= 7.9<\/p>","date":"2024-06-19"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4aa2a9957e346d4214493fedef81916536871b5161131b931f603c84d6856924","name":"SEOPress &#8211; AI SEO Plugin &amp; On-site SEO [wp-seopress] < 7.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-5488","name":"CVE-2024-5488","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-5488","description":"[en] The SEOPress  WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present.","date":"2024-07-09"},{"id":"311aa99c5cf429a17d9c526acc04ef5ca5d6f941","name":"WordPress SEOPress Plugin < 7.9 is vulnerable to PHP Object Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-seopress\/vulnerability\/wordpress-seopress-plugin-7-9-authentication-bypass-leading-to-php-object-injection-vulnerability","description":"<p>WordPress SEOPress Plugin < 7.9 is vulnerable to PHP Object Injection<\/p><p>Software: SEOPress<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wp-seopress\/#developers<\/p><p>Affected Version < 7.9<\/p><p>Fixed in version 7.9 <\/p>","date":"2024-07-09"},{"id":"ec9b826e223a2d2f74844c35df34da68f69dcca9","name":"SEOPress <= 7.8 - Unauthenticated PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-seopress\/seopress-78-unauthenticated-php-object-injection","description":"The SEOPress \u2013 On-site SEO plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.8 via deserialization of untrusted input from the 'title' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2024-06-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"22032bb074c69e02acc36c66605f211c340b856b7dd6c5b19b4b2798b5584ae4","name":"SEOPress &#8211; AI SEO Plugin &amp; On-site SEO [wp-seopress] < 8.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-9225","name":"CVE-2024-9225","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-9225","description":"[en] The SEOPress \u2013 On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 8.1.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2024-10-02"},{"id":"6dc0cc5abbda6589aec399af7f29d65efe0ff6c6","name":"SEOPress \u2013 On-site SEO <= 8.1.1 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-seopress\/seopress-on-site-seo-811-reflected-cross-site-scripting","description":"The SEOPress \u2013 On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 8.1.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2024-10-01"},{"id":"ec46df0865e1c14d2a3744aa2de7a6d25ec49656","name":"WordPress SEOPress Plugin <= 8.1.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-seopress\/vulnerability\/wordpress-seopress-plugin-8-1-1-reflected-cross-site-scripting-vulnerability","description":"<p>WordPress SEOPress Plugin <= 8.1.1 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: SEOPress<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wp-seopress\/#developers<\/p><p>Affected Version <= 8.1.1<\/p><p>Fixed in version 8.2 <\/p>","date":"2024-10-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"4cb2a6e118c215c27e6b452e68522fe818a785d0a5bf1e4da82c90b26bb421c5","name":"SEOPress &#8211; AI SEO Plugin &amp; On-site SEO [wp-seopress] < 8.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-50454","name":"CVE-2024-50454","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-50454","description":"[en] Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n\/a through <= 8.1.1.","date":"2024-10-29"},{"id":"5c321eec3c4858b69a5bc09f8c6ba94c3b8c1c61","name":"WordPress SEOPress Plugin <= 8.1.1 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-seopress\/vulnerability\/wordpress-seopress-plugin-8-1-1-unauthenticated-broken-access-control-vulnerability","description":"<p>WordPress SEOPress Plugin <= 8.1.1 is vulnerable to Broken Access Control<\/p><p>Software: SEOPress<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wp-seopress\/#developers<\/p><p>Affected Version <= 8.1.1<\/p><p>Fixed in version 8.2 <\/p>","date":"2024-10-24"},{"id":"aa36dfb8c321bdf3f8a32701c1152278ef345cf8","name":"SEOPress <= 8.1.1 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-seopress\/seopress-811-missing-authorization-2","description":"The SEOPress \u2013 On-site SEO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 8.1.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2024-10-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ab863f35f4ed303dcda51170e7b85e3e7e57a577de70fb58b3e752ef700cbe2d","name":"SEOPress &#8211; AI SEO Plugin &amp; On-site SEO [wp-seopress] < 8.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-50456","name":"CVE-2024-50456","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-50456","description":"[en] Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n\/a through <= 8.1.1.","date":"2024-10-29"},{"id":"c41ad412960a075fbee64e3f5e9cb2add5171b82","name":"WordPress SEOPress Plugin <= 8.1.1 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-seopress\/vulnerability\/wordpress-seopress-plugin-8-1-1-broken-access-control-vulnerability-2","description":"<p>WordPress SEOPress Plugin <= 8.1.1 is vulnerable to Broken Access Control<\/p><p>Software: SEOPress<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wp-seopress\/#developers<\/p><p>Affected Version <= 8.1.1<\/p><p>Fixed in version 8.2 <\/p>","date":"2024-10-24"},{"id":"8d332eb8c5e3fb6cb6b063ee7171f4a761c309ae","name":"SEOPress <= 8.1.1 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-seopress\/seopress-811-missing-authorization","description":"The SEOPress \u2013 On-site SEO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 8.1.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.","date":"2024-10-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"1e559d4dd7d5aae9e93ae5d06645d1fedfc36d7ab2b84cd58b3633369d9387b0","name":"SEOPress &#8211; AI SEO Plugin &amp; On-site SEO [wp-seopress] < 8.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-50455","name":"CVE-2024-50455","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-50455","description":"[en] Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n\/a through <= 8.1.1.","date":"2024-10-29"},{"id":"c18463fafc9c4ab09beaf9d2fddfd2fce4f3bffe","name":"WordPress SEOPress Plugin <= 8.1.1 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-seopress\/vulnerability\/wordpress-seopress-plugin-8-1-1-broken-access-control-vulnerability","description":"<p>WordPress SEOPress Plugin <= 8.1.1 is vulnerable to Broken Access Control<\/p><p>Software: SEOPress<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wp-seopress\/#developers<\/p><p>Affected Version <= 8.1.1<\/p><p>Fixed in version 8.2 <\/p>","date":"2024-10-24"},{"id":"9d9d6ec84fdb03181aaf2c074b080656d5c2c62c","name":"SEOPress <= 8.1.1 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-seopress\/seopress-811-missing-authorization-1","description":"The SEOPress \u2013 On-site SEO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 8.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.","date":"2024-10-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e5daff6d7b0332b1f383f42f65f66399a5edd1e7e8dbe6a99ff4e20a7dfe5fb9","name":"SEOPress &#8211; AI SEO Plugin &amp; On-site SEO [wp-seopress] < 10.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"10.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-85305","name":"CVE-2026-85305","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-85305","description":"[en] Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery.\n\nThis issue affects SEOPress: from n\/a through 10.1.","date":"2026-09-03"},{"id":"79763a4f1379c1921a3f62d75b25c8b890bba3ef","name":"WordPress SEOPress Plugin <= 10.1 is vulnerable to Server Side Request Forgery (SSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-seopress\/vulnerability\/wordpress-seopress-plugin-10-1-server-side-request-forgery-ssrf-vulnerability","description":"<p>WordPress SEOPress Plugin <= 10.1 is vulnerable to Server Side Request Forgery (SSRF)<\/p><p>Software: SEOPress<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wp-seopress\/<\/p><p>Fixed in version 10.2 <\/p><p>Affected Version <= 10.1<\/p><p>CVE: CVE-2026-85305<\/p>","date":"2026-09-03"},{"id":"5ab043020179ebc610b57e29c2023ba964fd7f69","name":"SEOPress \u2013 AI SEO Plugin & On-site SEO <= 10.1 - Authenticated (Contributor+) Server-Side Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-seopress\/seopress-ai-seo-plugin-on-site-seo-101-authenticated-contributor-server-side-request-forgery","description":"The SEOPress \u2013 AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 10.1. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.","date":"2024-10-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-918","name":"Server-Side Request Forgery (SSRF)","description":"The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1789030704"}