WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Siteseo?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Siteseo — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: siteseo
  • 500000+ instalaciones activas

meta descriptionschemaseoxml sitemap

Estado de mantenimiento

  • Última versión conocida: 1.4.0
  • Requiere PHP: 7.2+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

4 CVEs conocidos registrados para Siteseo.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2025-12814 SiteSEO – SEO Simplified [siteseo] < 1.3.3 Autorización indebida Media 5,3 < 1.3.3 1.3.3 2025-11-18 ✓ corregido en la última versión
CVE-2025-13085 SiteSEO – SEO Simplified [siteseo] < 1.3.3 Autorización indebida Media 4,3 < 1.3.3 1.3.3 2025-11-18 ✓ corregido en la última versión
CVE-2025-12367 SiteSEO – SEO Simplified [siteseo] < 1.3.2 Autorización indebida Media 4,3 < 1.3.2 1.3.2 2025-10-31 ✓ corregido en la última versión
CVE-2025-9277 SiteSEO – SEO Simplified [siteseo] < 1.2.8 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 1.2.8 1.2.8 0000-00-00 ✓ corregido en la última versión

CVE-2025-12814

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to unauthorized modification of data due to n incorrect capability check on the siteseo_reset_settings function in all versions up to, and including, 1.3.2. This makes it possible for authenticated attackers, who have been granted access to at least on SiteSEO setting capability, to reset the plugin's settings.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-13085

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Improper Authorization leading to Sensitive Post Meta Disclosure in versions up to and including 1.3.2. This is due to missing object-level authorization checks in the resolve_variables() AJAX handler. This makes it possible for authenticated attackers with the siteseo_manage capability (e.g., Author-level users who have been granted SiteSEO access by an administrator) to read arbitrary post metadata from any post, page, attachment, or WooCommerce order they cannot edit, via the custom field variable resolution feature granted they have been given access to SiteSEO by an administrator and legacy storage is enabled. In affected WooCommerce installations, this exposes sensitive customer billing information including names, email addresses, phone numbers, physical addresses, and payment methods.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-12367

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.3.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Author-level access and above, to enable or disable arbitrary SiteSEO features that they should not have access to.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-9277

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the broken preg_replace expression in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Cómo solucionarlo

Mantén Siteseo actualizado — 1.4.0 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.