Extension WordPress

Vulnérabilités SEOPress – AI SEO Plugin & On-site SEO

Cette page rassemble les failles publiées pour SEOPress – AI SEO Plugin & On-site SEO, leurs plages de versions affectées et les correctifs signalés dans la base locale.

14Vulnérabilités
1Critiques
14Avec correctif
9,0CVSS maximal

Historique de sécurité

CVE et vulnérabilités de SEOPress – AI SEO Plugin & On-site SEO

14 fiches

CVE-2024-1168 Moyenne · 6,4
SEOPress – AI SEO Plugin & On-site SEO

SEOPress – On-site SEO <= 7.9 – Authenticated(Contributor+) Stored Cross-Site Scripting via Social Image URL

The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's social image URL in all versions up to, and including, 7.9 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-7.9

Correctif

7.9.1

Publication

19/06/2024

CVE-2024-1134 Moyenne · 6,4
SEOPress – AI SEO Plugin & On-site SEO

SEOPress – On-site SEO <= 7.5.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SEO title and description parameters as well as others in all versions up to, and including, 7.5.2.1 due to insufficient input sanitization…

Versions affectées

*-7.5.2.1

Correctif

7.6

Publication

23/05/2024

CVE-2024-2165 Moyenne · 6,4
SEOPress – AI SEO Plugin & On-site SEO

SEOPress – On-site SEO <= 7.5.2.1 – Authenticated (Author+) Stored Cross-Site Scripting

The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt parameter in all versions up to, and including, 7.5.2.1 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-7.5.2.1

Correctif

7.6

Publication

22/03/2024

CVE-2023-1669 Moyenne · 6,6
SEOPress – AI SEO Plugin & On-site SEO

SEOPress <= 6.5.0.2 – Authenticated (Administrator+) PHP Object Injection

The SEOPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.5.0.2 via deserialization of untrusted input of the $redirect_value['sources'] value triggered to an import with the seopress_import_rk_redirections function. This allows authenticated…

Versions affectées

*-6.5.0.2

Correctif

6.5.0.3

Publication

05/04/2023

CVE-2021-34641 Moyenne · 6,4
SEOPress – AI SEO Plugin & On-site SEO

SEOPress 5.0.0 – 5.0.3 – Stored Cross-Site Scripting

The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/src/Actions/Api/TitleDescriptionMeta.php file which allows authenticated attackers to inject arbitrary web scripts, in versions 5.0.0 – 5.0.3.

Versions affectées

5.0.0, 5.0.1, 5.0.2, 5.0.3

Correctif

5.0.4

Publication

16/08/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités