WPHizmet

Eklenti güvenlik geçmişi

SEOPress güvenlik açıkları

ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) SEOPress – AI SEO Plugin & On-site SEO eklentisi için 15 açık kaydı bulunuyor; en yenisi 3 Ekim 2026 tarihli. Bunların 5 tanesi kritik veya yüksek önemde, 7 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 10.3.

Toplam kayıt
15
Kritik veya yüksek
5
Oturumsuz istismar
7
Son kayıt
3 Ekim 2026

Bilinen açık kayıtları

En yeniden eskiye. Her kaydın özgün metni NVD’de.

  • CVE-2026-96564Yüksek · 7,23 Ekim 2026

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 10.2 ve öncesi · Oturum açmadan istismar edilebilir

    The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Author Display Name in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the 'Track Authors' custom dimension to be configured in the plugin's Google Analytics 4 or Matomo settings, and the attacker must be able to publish public singular content (e.g., via bbPress forum topics) so that the injected display name is rendered in the tracking script.

    Türkçe kayıt ve ne yapmalı
  • CVE-2026-101357Orta · 4,93 Ekim 2026

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 10.2 ve öncesi

    The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'seopress_google_analytics_matomo_id' parameter in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires an administrator to have delegated the Analytics management capability to the Subscriber role via the plugin's Advanced > Security settings.

  • CVE-2026-85305Orta · 5,43 Eylül 2026

    sunucu taraflı istek sahteciliği (SSRF)

    Etkilenen sürümler: 10.1 ve öncesi

    Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEOPress: from n/a through 10.1.

  • CVE-2024-50454Orta · 5,330 Ekim 2024

    eksik yetki denetimi

    Etkilenen sürümler: 8.1.1 ve öncesi · Oturum açmadan istismar edilebilir

    Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n/a through <= 8.1.1.

  • CVE-2024-50456Yüksek · 8,830 Ekim 2024

    eksik yetki denetimi

    Etkilenen sürümler: 8.1.1 ve öncesi

    Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n/a through <= 8.1.1.

  • CVE-2024-50455Yüksek · 8,830 Ekim 2024

    eksik yetki denetimi

    Etkilenen sürümler: 8.1.1 ve öncesi

    Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n/a through <= 8.1.1.

  • CVE-2024-9225Orta · 6,12 Ekim 2024

    yansıtılan siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 8.1.1 ve öncesi · Oturum açmadan istismar edilebilir

    The SEOPress – On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 8.1.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

  • CVE-2024-5488Kritik · 9,89 Temmuz 2024

    PHP nesne enjeksiyonu

    Etkilenen sürümler: 7.9 öncesi · Oturum açmadan istismar edilebilir

    The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present.

  • CVE-2024-4900Orta · 6,124 Haziran 2024

    açık yönlendirme

    Etkilenen sürümler: 7.8 öncesi · Oturum açmadan istismar edilebilir

    The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perform Open redirect attacks against any user viewing a malicious post

  • CVE-2024-4899Orta · 5,024 Haziran 2024

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 7.8 öncesi · Oturum açmadan istismar edilebilir

    The SEOPress WordPress plugin before 7.8 does not sanitise and escape some of its Post settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.

  • CVE-2024-1168Orta · 5,420 Haziran 2024

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 7.9 ve öncesi

    The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's social image URL in all versions up to, and including, 7.9 due to insufficient input sanitization and output escaping on user supplied image URLs. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

  • CVE-2024-34383Orta · 5,36 Mayıs 2024

    yetkisiz nesne erişimi (IDOR)

    Etkilenen sürümler: 7.7.1 ve öncesi · Oturum açmadan istismar edilebilir

    Authorization Bypass Through User-Controlled Key vulnerability in The SEO Guys at SEOPress SEOPress.This issue affects SEOPress: from n/a through 7.7.1.

  • CVE-2023-6290Orta · 4,822 Ocak 2024

    siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 7.3 öncesi

    The SEOPress WordPress plugin before 7.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

  • CVE-2023-1669Yüksek · 7,22 Mayıs 2023

    PHP nesne enjeksiyonu

    Etkilenen sürümler: 6.5.0.3 öncesi

    The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

  • CVE-2021-34641Orta · 5,416 Ağustos 2021

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: Kayıtta belirtilmemiş

    The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/src/Actions/Api/TitleDescriptionMeta.php file which allows authenticated attackers to inject arbitrary web scripts, in versions 5.0.0 - 5.0.3.

Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 8 Ekim 2026 itibarıyla.