CVE Database /
CVE-2024-9225
CVE · Medium
CVE-2024-9225 — SEOPress – AI SEO Plugin & On-site SEO [wp-seopress] < 8.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-9225
|
SEOPress – AI SEO Plugin & On-site SEO [wp-seopress] < 8.2 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 8.2
|
8.2 |
2024-10-01 |
—
|
CVE-2024-9225
The SEOPress plugin for WordPress has a security flaw affecting all versions up to and including 8.1.1, which allows malicious actors to inject unauthorized code onto targeted websites through carefully crafted URLs. This vulnerability arises from the inadequate sanitization of URL parameters when using certain functions. As a result, unauthenticated attackers can potentially execute arbitrary scripts on affected sites by manipulating user behavior.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings