Input validation vulnerability in SEOPress – On-site SEO 7.7.2

The SEOPress plugin for WordPress has a security issue that allows attackers to inject harmful web scripts into pages. This can happen because the plugin does not properly check the input and output of the SEO Title field. This vulnerability affects all versions of the plugin up to version 7.7.2. Attackers with Contributor-level access or higher can take advantage of this vulnerability.

Detected in:

SEOPress – On-site SEO fixed vulnerable versions: >= * <= 7.7.2
SEOPress – On-site SEO & Analytics fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.