← Vulnerability feed

Vulnerability record · CVE-2024-9225 · published 2 October 2024

CVE-2024-9225: Seopress cross-site scripting vulnerability

Seopress · Seopress

The SEOPress – On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 8.1.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

6.1 CVSS 3.1 Medium EPSS 0.45% · top 63.2% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
0.45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

The SEOPress – On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 8.1.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-9225 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-5488Seopress deserialization of untrusted data vulnerabilityThe SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerab…EPSS 3.7%8.8CVE-2024-50455Seopress missing authorization vulnerabilityMissing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.Th…EPSS 0.36%8.8CVE-2024-50456Seopress missing authorization vulnerabilityMissing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.Th…EPSS 0.29%7.2CVE-2023-1669Seopress deserialization of untrusted data vulnerabilityThe SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin …EPSS 18%6.1CVE-2024-4900Seopress open redirect vulnerabilityThe SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perfo…EPSS 0.33%5.4CVE-2024-1168Seopress cross-site scripting vulnerabilityThe SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's social image URL in all versions up to,…EPSS 0.37%5.4CVE-2024-1134Seopress cross-site scripting vulnerabilityThe SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SEO title and description parameters as well as …EPSS 0.26%5.4CVE-2024-2165Seopress improper input validation vulnerabilityThe SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image alt parameter in all versions up to, and i…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2024-9225), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.