Eklenti güvenlik geçmişi
SEOPress güvenlik açıkları
ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) SEOPress – AI SEO Plugin & On-site SEO eklentisi için 15 açık kaydı bulunuyor; en yenisi 3 Ekim 2026 tarihli. Bunların 5 tanesi kritik veya yüksek önemde, 7 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 10.3.
- Toplam kayıt
- 15
- Kritik veya yüksek
- 5
- Oturumsuz istismar
- 7
- Son kayıt
- 3 Ekim 2026
Bilinen açık kayıtları
En yeniden eskiye. Her kaydın özgün metni NVD’de.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 10.2 ve öncesi · Oturum açmadan istismar edilebilir
The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Author Display Name in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the 'Track Authors' custom dimension to be configured in the plugin's Google Analytics 4 or Matomo settings, and the attacker must be able to publish public singular content (e.g., via bbPress forum topics) so that the injected display name is rendered in the tracking script.
Türkçe kayıt ve ne yapmalıdepolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 10.2 ve öncesi
The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'seopress_google_analytics_matomo_id' parameter in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires an administrator to have delegated the Analytics management capability to the Subscriber role via the plugin's Advanced > Security settings.
sunucu taraflı istek sahteciliği (SSRF)
Etkilenen sürümler: 10.1 ve öncesi
Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEOPress: from n/a through 10.1.
eksik yetki denetimi
Etkilenen sürümler: 8.1.1 ve öncesi · Oturum açmadan istismar edilebilir
Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n/a through <= 8.1.1.
eksik yetki denetimi
Etkilenen sürümler: 8.1.1 ve öncesi
Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n/a through <= 8.1.1.
eksik yetki denetimi
Etkilenen sürümler: 8.1.1 ve öncesi
Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n/a through <= 8.1.1.
yansıtılan siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 8.1.1 ve öncesi · Oturum açmadan istismar edilebilir
The SEOPress – On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 8.1.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
PHP nesne enjeksiyonu
Etkilenen sürümler: 7.9 öncesi · Oturum açmadan istismar edilebilir
The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present.
açık yönlendirme
Etkilenen sürümler: 7.8 öncesi · Oturum açmadan istismar edilebilir
The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perform Open redirect attacks against any user viewing a malicious post
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 7.8 öncesi · Oturum açmadan istismar edilebilir
The SEOPress WordPress plugin before 7.8 does not sanitise and escape some of its Post settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 7.9 ve öncesi
The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's social image URL in all versions up to, and including, 7.9 due to insufficient input sanitization and output escaping on user supplied image URLs. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
yetkisiz nesne erişimi (IDOR)
Etkilenen sürümler: 7.7.1 ve öncesi · Oturum açmadan istismar edilebilir
Authorization Bypass Through User-Controlled Key vulnerability in The SEO Guys at SEOPress SEOPress.This issue affects SEOPress: from n/a through 7.7.1.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 7.3 öncesi
The SEOPress WordPress plugin before 7.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
PHP nesne enjeksiyonu
Etkilenen sürümler: 6.5.0.3 öncesi
The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: Kayıtta belirtilmemiş
The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/src/Actions/Api/TitleDescriptionMeta.php file which allows authenticated attackers to inject arbitrary web scripts, in versions 5.0.0 - 5.0.3.
Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 8 Ekim 2026 itibarıyla.