PT-2022-14013 · WordPress · Simple Seo
Jörgson
·
Published
2022-09-06
·
Updated
2022-09-09
·
CVE-2022-1628
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Simple SEO plugin for WordPress versions up to, and including 1.7.91
Description
The issue is related to attribute-based stored Cross-Site Scripting due to insufficient sanitization or escaping on the
SEO social and standard title parameters. This can be exploited by authenticated users with Contributor and above permissions to inject arbitrary web scripts into posts/pages that execute whenever an administrator accesses the page.Recommendations
For Simple SEO plugin for WordPress versions up to, and including 1.7.91, update to a version that includes proper sanitization or escaping of the SEO social and standard title parameters to prevent Cross-Site Scripting. As a temporary workaround, consider restricting access to the SEO social and standard title parameters for users with Contributor and above permissions until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple Seo