The Simple SEO plugin for WordPress is vulnerable to attribute-based stored Cross-Site Scripting in versions up to, and including 1.7.91, due to insufficient sanitization or escaping on the SEO social and standard title parameters. This can be exploited by authenticated users with Contributor and above permissions to inject arbitrary web scripts into posts/pages that execute whenever an administrator access the page.
Metrics
Affected Vendors & Products
References
History
Fri, 31 Jan 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2022-09-06T17:18:55.000Z
Updated: 2025-01-31T18:51:59.157Z
Reserved: 2022-05-09T00:00:00.000Z
Link: CVE-2022-1628

Updated: 2024-08-03T00:10:03.751Z

Status : Modified
Published: 2022-09-06T18:15:10.423
Modified: 2024-11-21T06:41:07.740
Link: CVE-2022-1628

No data.