CVE-2024-4899: SEOPress < 7.8 - Contributor+ Stored XSS
Published Jun 24, 2024
·Updated
The SEOPress WordPress plugin before 7.8 does not sanitise and escape some of its Post settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.
Affected Software
2 affected components
SEOPress SEOPress<7.8
SEOPress SEOPress WordPress<7.8
Event History
Jun 24, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-4899?
CVE-2024-4899 has a medium severity rating due to the potential for stored Cross-Site Scripting attacks.
2
How do I fix CVE-2024-4899?
To fix CVE-2024-4899, update the SEOPress plugin to version 7.8 or later.
3
Who is affected by CVE-2024-4899?
CVE-2024-4899 affects users of the SEOPress plugin version before 7.8, particularly those with high privilege roles.
4
What type of vulnerability is CVE-2024-4899?
CVE-2024-4899 is a Stored Cross-Site Scripting (XSS) vulnerability.
5
Can contributors exploit CVE-2024-4899?
Yes, high privilege users such as contributors can exploit CVE-2024-4899 to perform stored XSS attacks.