CVE-2024-9225
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Oct 2, 2024
Updated: Oct 7, 2024
CWE ID 79
Summary
CVE-2024-9225: The SEOPress plugin for WordPress, used for on-site SEO, contains a Reflected Cross-Site Scripting (XSS) vulnerability. This issue arises due to the lack of proper escaping when using add_query_arg and remove_query_arg functions in handling URLs. As a result, unauthenticated attackers can inject arbitrary web scripts into pages by tricking users into performing specific actions, such as clicking on malicious links. This can lead to potential security breaches and unintended functionality changes. Versions up to 8.1.1 of the plugin are affected.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- SEOPress Pro