CVE-2021-34641: SEOPress <= 5.0.0 – 5.0.3 Authenticated Stored Cross-Site Scripting
The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/src/Actions/Api/TitleDescriptionMeta.php file which allows authenticated attackers to inject arbitrary web scripts, in versions 5.0.0 - 5.0.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-34641?
CVE-2021-34641 is considered a medium severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2021-34641?
To fix CVE-2021-34641, update the SEOPress plugin to version 5.0.4 or later.
Who is affected by CVE-2021-34641?
CVE-2021-34641 affects users of the SEOPress WordPress plugin versions 5.0.0 to 5.0.3.
What type of attack can CVE-2021-34641 enable?
CVE-2021-34641 can enable authenticated attackers to perform stored cross-site scripting attacks allowing injection of arbitrary web scripts.
What is SEOPress?
SEOPress is a WordPress plugin designed to improve the SEO of websites, which is affected by CVE-2021-34641.