← Vulnerability feed

Vulnerability record · CVE-2024-1134 · published 24 May 2024

CVE-2024-1134: Seopress cross-site scripting vulnerability

Seopress · Seopress

The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SEO title and description parameters as well as others in all versions up to, and including, 7.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

5.4 CVSS 3.1 Medium EPSS 0.26% · top 84.4% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score
0.26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SEO title and description parameters as well as others in all versions up to, and including, 7.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-1134 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-5488Seopress deserialization of untrusted data vulnerabilityThe SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerab…EPSS 3.7%8.8CVE-2024-50455Seopress missing authorization vulnerabilityMissing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.Th…EPSS 0.36%8.8CVE-2024-50456Seopress missing authorization vulnerabilityMissing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.Th…EPSS 0.29%7.2CVE-2023-1669Seopress deserialization of untrusted data vulnerabilityThe SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin …EPSS 18%6.1CVE-2024-9225Seopress cross-site scripting vulnerabilityThe SEOPress – On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg wi…EPSS 0.45%6.1CVE-2024-4900Seopress open redirect vulnerabilityThe SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perfo…EPSS 0.33%5.4CVE-2024-1168Seopress cross-site scripting vulnerabilityThe SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's social image URL in all versions up to,…EPSS 0.37%5.4CVE-2024-2165Seopress improper input validation vulnerabilityThe SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt parameter in all versions up to, and i…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2024-1134), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.