CVE · Medium

CVE-2024-9225 — SEOPress – AI SEO Plugin & On-site SEO [wp-seopress] < 8.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-9225 SEOPress – AI SEO Plugin & On-site SEO [wp-seopress] < 8.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 8.2 8.2 2024-10-01

CVE-2024-9225

The SEOPress plugin for WordPress has a security flaw affecting all versions up to and including 8.1.1, which allows malicious actors to inject unauthorized code onto targeted websites through carefully crafted URLs. This vulnerability arises from the inadequate sanitization of URL parameters when using certain functions. As a result, unauthenticated attackers can potentially execute arbitrary scripts on affected sites by manipulating user behavior.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.