Vulnerabilities
Vulnerable Software
Seopress:  >> Seopress  >> 5.0.2  Security Vulnerabilities
The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
CVSS Score
7.2
EPSS Score
0.177
Published
2023-05-02
The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/src/Actions/Api/TitleDescriptionMeta.php file which allows authenticated attackers to inject arbitrary web scripts, in versions 5.0.0 - 5.0.3.
CVSS Score
6.4
EPSS Score
0.002
Published
2021-08-16


Contact Us

Shodan ® - All rights reserved