CVE-2026-85305: WordPress SEOPress plugin <= 10.1 - Server Side Request Forgery (SSRF) vulnerability
Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery.
This issue affects SEOPress: from n/a through 10.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress SEOPress Pluginto a version that resolves this vulnerability.Fixed in 10.2
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs low-level privileges and user interaction. It is network-reachable and has low attack complexity.
What is the likely impact if exploitation succeeds?
The vulnerability can allow server-side requests to attacker-chosen targets. The recorded impact is low confidentiality and integrity impact, with no availability impact, and the scope may extend beyond the vulnerable component.
Which SEOPress versions are affected?
SEOPress versions through 10.1 are affected. The earliest affected version is not specified.