CVE · Medium

CVE-2024-2165 — SEOPress – AI SEO Plugin & On-site SEO [wp-seopress] < 7.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-2165 SEOPress – AI SEO Plugin & On-site SEO [wp-seopress] < 7.6 Improper Input Validation Medium 5.4 < 7.6 7.6 2024-03-22

CVE-2024-2165

The SEOPress plugin versions prior to 7.6 contain a cross-site scripting vulnerability that enables attackers to inject harmful scripts into websites, potentially resulting in redirects, unwanted advertisements, and malicious HTML being executed for site visitors. Researcher Ngô Thiên An discovered this flaw, which has been resolved in version 7.6 and later. Users should upgrade their installations to version 7.6 or newer to eliminate this security risk.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.