CVE-2024-1168

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's social image URL in all versions up to, and including, 7.9 due to insufficient input sanitization and output escaping on user supplied image URLs. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<h3>SEOPress – The fast, privacy-first WordPress SEO plugin, ready for AI search</h3> <p><strong>Rank higher in Google AND in AI answer engines</strong> (ChatGPT, Claude, Perplexity, Gemini). SEOPress is the all-in-one WordPress SEO plugin trusted by <strong>350,000+ websites since 2017</strong>: fully white label, <strong>privacy by design</strong>, and now AI-ready.</p> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/4ysKFVr_nu0?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <p>✔ <strong>One SEO plugin, every page builder</strong>: Universal SEO metabox for Gutenberg, Elementor, Divi, Bricks, Oxygen, Breakdance, WPBakery, Avada, Kadence and more. <a href="https://www.seopress.org/features/page-builders-integration/" rel="nofollow ugc">See all integrations</a>.<br /> ✔ <strong>AI-powered metadata</strong>: Generate SEO titles, meta descriptions, Open Graph, X (Twitter) Cards and image alt text in bulk with OpenAI, Google Gemini, Anthropic Claude, MistralAI or DeepSeek. <a href="https://www.seopress.org/features/openai/" rel="nofollow ugc">Learn more</a>.<br /> ✔ <strong>Built for AI search (AEO / GEO)</strong>: Native llms.txt support and one-click Agent Readiness toggle so ChatGPT, Claude, Perplexity &amp; Gemini understand your content.<br /> ✔ <strong>Privacy-first &amp; fully white label</strong>: No tracking, no data footprint, no upsells in admin. Your data stays yours. <a href="https://www.seopress.org/features/seopress-white-label/" rel="nofollow ugc">Why white label matters</a>.<br /> ✔ <strong>Content analysis with unlimited target keywords</strong>: No artificial limit per post.<br /> ✔ <strong>Migrate in one click</strong>: From Yoast SEO, Rank Math, AIOSEO, The SEO Framework, Slim SEO, SmartCrawl, Squirrly, SEO Ultimate, WP Meta SEO, Premium SEO Pack, SiteSEO. <a href="https://www.seopress.org/solutions/migrate-from/" rel="nofollow ugc">Start migration</a>.<br /> ✔ <strong>Translated into 27+ languages</strong> with professional translations. <a href="https://translate.wordpress.org/projects/wp-plugins/wp-seopress" rel="nofollow ugc">Help translate</a>.</p> <p><a href="https://www.seopress.org/pricing/" rel="nofollow ugc"><strong>SEOPress PRO from $49/year: 1 site • Unlimited sites for $149/year</strong></a></p> <p><a href="https://www.seopress.org/features/" rel="nofollow ugc">Features</a> | <a href="https://www.seopress.org/solutions/migrate-from/" rel="nofollow ugc">Migrate</a> | <a href="https://www.seopress.org/wordpress-seo-plugins/pro/" rel="nofollow ugc">PRO</a> | <a href="https://www.seopress.org/integrations/" rel="nofollow ugc">Integrations</a> | <a href="https://www.seopress.org/support/" rel="nofollow ugc">Support</a> | <a href="https://www.seopress.org/features/seopress-white-label/" rel="nofollow ugc">White Label</a> | <a href="https://www.seopress.org/features/openai/" rel="nofollow ugc">AI</a></p> <h3>What&#8217;s new in SEOPress 9.9</h3> <p>A major UX release: redesigned SEO dashboard, smarter SEO box, sharper Content Analysis and a fully accessible admin.</p> <ul> <li><strong>🧭 Brand new SEO dashboard &amp; admin header</strong>: Cleaner two-column layout, one-click module toggles, guided &#8220;Get Started&#8221; with numbered steps, and quick access to Help, Display options and notifications (with counter badge) on every SEO page.</li> <li><strong>🪄 Setup wizard, fully redesigned</strong>: Faster, mobile-friendly, and easier to follow from start to finish.</li> <li><strong>⚡ Smarter SEO box</strong>: Double-click target keywords to edit in place, Google keyword suggestions with autocomplete as you type, and a single &#8220;Update&#8221; in the Block Editor now saves every section at once (Title, Description, Advanced, Social, Redirections, Content Analysis).</li> <li><strong>📝 Content Analysis</strong>: New content quality &amp; structure checks to help you write better articles, plus the ability to hide an issue you don&#8217;t want to fix on a given page.</li> <li><strong>🔄 One-click migration from SureRank</strong> and a full migration from SmartCrawl (variables in your titles &amp; descriptions are automatically translated).</li> <li><strong>🛠️ Tools redesigned</strong>: Reset page with confirmation prompts so nothing happens by accident, and Import / Export with a cleaner layout, &#8220;export everything&#8221; by default, and a Cancel button on CSV exports.</li> <li><strong>👁️ Appearance › Columns</strong>: Live preview of your post lists with grouped checkboxes — see what you&#8217;ll get before you save.</li> <li><strong>♿ Big accessibility upgrade</strong> across the whole SEO admin (WCAG 2.1 AA / RGAA 4.1 compliant), and the admin now matches your WordPress color scheme automatically.</li> <li><strong>📊 Site Overview on the dashboard</strong> (PRO): Your Google Analytics 4 and Matomo stats directly on the SEO dashboard, with period &amp; metric filters, an interactive chart, and a sync button.</li> <li><strong>🎬 Video schema auto-filled</strong> (PRO): Populated from the first YouTube video found in your post — no manual copy-paste.</li> <li><strong>↪️ Redirections</strong> (PRO): Quick Edit, search results that stay when you go back, search by destination URL, and a dedicated 404 view with a &#8220;Delete 404s&#8221; shortcut.</li> <li><strong>🩺 Site Audit</strong> (PRO): Detects the new content quality &amp; structure issues.</li> <li><strong>🌍 Better Search Console URL matching</strong> (PRO) for multilingual sites (WPML / Polylang).</li> </ul> <p><a href="https://www.seopress.org/newsroom/product-news/seopress-9-9/" rel="nofollow ugc"><strong>Read the full 9.9 release notes <span aria-hidden="true" class="wp-exclude-emoji">→</span></strong></a></p> <h3>Why SEOPress is the best WordPress SEO plugin?</h3> <ul> <li><strong>All-in-one</strong>: Schemas, redirections, XML sitemaps, GSC, image SEO, breadcrumbs, broken links and more in one plugin. Fewer plugins, fewer conflicts, lower maintenance.</li> <li><strong>Modular</strong>: Don&#8217;t need a feature? Disable it in one click without losing your settings.</li> <li><strong>Affordable</strong>: PRO from $49/year for 1 site. Unlimited sites for $149/year. No &#8220;agency&#8221; tax.</li> <li><strong>White label by default</strong>: Replace plugin name, logo, links and screens. Perfect for agencies and freelancers.</li> <li><strong>GDPR-friendly</strong>: Privacy by design. Built-in compatibility with consent platforms.</li> <li><strong>Beginner to expert</strong>: Installation wizard for newcomers, hundreds of hooks, REST API and WP-CLI for developers. Free <a href="https://www.seopress.org/support/" rel="nofollow ugc">guides</a> and <a href="https://www.seopress.org/support/ebooks/" rel="nofollow ugc">SEO ebooks</a>.</li> <li><strong>Battle-tested</strong>: 350,000+ active installs, weekly releases, dedicated team since 2017.</li> </ul> <h3>SEOPress Free Features</h3> <ul> <li><strong>Installation wizard</strong>: Get configured in minutes.</li> <li><strong>Universal SEO metabox</strong>: Edit titles, descriptions, Open Graph, X Cards, schema, robots and canonical from any editor (Gutenberg, Elementor, Divi, Bricks, Oxygen, Breakdance, WPBakery, Avada, Kadence…).</li> <li><strong>Command palette</strong> (Cmd/Ctrl+K): Jump to any setting instantly.</li> <li><strong>Content analysis</strong> with **unlimited target keywords** to write content that ranks.</li> <li><strong>Mobile &amp; Desktop Google preview</strong>: See your SERP snippet before you publish.</li> <li><strong>Facebook &amp; X (Twitter) social preview</strong> for higher CTR on social.</li> <li><strong>Titles &amp; meta descriptions</strong> with <a href="https://www.seopress.org/support/guides/manage-titles-meta-descriptions/" rel="nofollow ugc">dynamic variables</a> (custom fields, terms, taxonomies).</li> <li><strong>Open Graph &amp; X (Twitter) Cards</strong> for Facebook, LinkedIn, Instagram, Pinterest, WhatsApp, Threads…</li> <li><strong>Google Knowledge Graph</strong>: Organization data with address &amp; legal fields (new in 9.8).</li> <li><strong>llms.txt &amp; Agent Readiness</strong>: Help AI search engines understand your site (new in 9.8).</li> <li><strong>Google Analytics 4 &amp; Matomo</strong>: Downloads tracking, custom dimensions, IP anonymization, remarketing, demographics, cross-domain tracking, GDPR-friendly.</li> <li><strong>Microsoft Clarity</strong> integration: Free heatmaps and session recordings.</li> <li><strong>Custom canonical URLs</strong> and <a href="https://www.seopress.org/support/guides/manage-meta-robots/" rel="nofollow ugc">meta robots</a> (noindex, nofollow, noimageindex, nosnippet).</li> <li><strong>XML sitemaps</strong> (posts, pages, CPTs, taxonomies, images, authors): <a href="https://www.seopress.org/features/sitemaps/" rel="nofollow ugc">faster than ever</a> in 9.8.</li> <li><strong>HTML sitemap</strong> for accessibility &amp; navigation.</li> <li><strong>Image XML sitemap</strong> for Google Images.</li> <li><strong>Redirections</strong> at the post / page / CPT level.</li> <li><strong>URL clean-up</strong>: Remove /category/, /product-category/, ?replytocom; redirect attachment pages to parent or file URL.</li> <li><a href="https://www.seopress.org/features/image-seo/" rel="nofollow ugc"><strong>Image SEO</strong></a>: Auto-set image title, alt, caption and description.</li> <li><a href="https://www.seopress.org/support/guides/google-indexing-api-with-seopress/" rel="nofollow ugc"><strong>Google Indexing API &amp; IndexNow</strong></a> (Bing/Yandex) for instant indexing.</li> <li><strong>Import/export settings</strong> from site to site.</li> <li><strong>One-click migration</strong> from Yoast, Rank Math, AIOSEO, SEO Framework, SureRank, Slim SEO, SmartCrawl, Squirrly, SEO Ultimate, WP Meta SEO, Premium SEO Pack, SiteSEO.</li> </ul> <p><a href="https://www.seopress.org/wordpress-seo-plugins/free/features/" rel="nofollow ugc">Check out all SEOPress Free features here</a></p> <h3>SEOPress PRO: Take SEO further</h3> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/zxGCY-bJYwE?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <ul> <li><a href="https://www.seopress.org/features/openai/" rel="nofollow ugc"><strong>AI SEO</strong></a>: Auto-generate titles, descriptions, OG / X tags and image alt text in bulk with OpenAI, Google Gemini (incl. **Gemini 3 Flash &amp; 3.1 Pro**), Anthropic Claude, MistralAI, DeepSeek.</li> <li><a href="https://www.seopress.org/features/site-audit/" rel="nofollow ugc"><strong>Site Audit</strong></a>: Full React + DataViews experience with **GSC-backed recommendations**, scan history, live progress, one-click AI alt text fixes, CSV export.</li> <li><a href="https://www.seopress.org/features/seo-alerts/" rel="nofollow ugc"><strong>SEO alerts</strong></a>: Be warned before SEO regressions hit production.</li> <li><a href="https://www.seopress.org/features/google-search-console/" rel="nofollow ugc"><strong>Google Search Console</strong></a>: Clicks, impressions, CTR, average position right inside post lists.</li> <li><a href="https://www.seopress.org/features/google-suggest/" rel="nofollow ugc"><strong>Google Suggestions</strong></a> in content analysis for long-tail keyword discovery.</li> <li><a href="https://www.seopress.org/features/301-redirects/" rel="nofollow ugc"><strong>Redirect manager</strong></a>: Unlimited 301/302/307/410/451 redirects, regex, URL tester modal, categories, CSV/htaccess import &amp; export.</li> <li><strong>404 monitoring &amp; auto-redirect</strong> with email notifications.</li> <li><strong>Broken link checker</strong>: Reliable CRON-based batch scan, even on the largest sites.</li> <li><a href="https://www.seopress.org/features/google-structured-data-types/" rel="nofollow ugc"><strong>Schema.org / JSON-LD editor</strong></a> with **live preview**: Article, LocalBusiness, Service, How-to, FAQ, Course, Recipe, SoftwareApplication, Video, Event, Product, JobPosting, Review, ProfilePage, Custom schema.</li> <li><strong>Automatic schemas</strong> with advanced conditions (AND/OR, post types, taxonomies).</li> <li><a href="https://www.seopress.org/features/breadcrumbs/" rel="nofollow ugc"><strong>Accessible breadcrumbs</strong></a>: Schema.org, A11Y-ready, live preview, custom per CPT/term.</li> <li><a href="https://www.seopress.org/features/local-seo/" rel="nofollow ugc"><strong>Local SEO</strong></a>: Local Business schema with opening hours, multiple stores.</li> <li><a href="https://www.seopress.org/features/woocommerce-seo/" rel="nofollow ugc"><strong>WooCommerce SEO</strong></a>: Product schema with global identifiers (GTIN, MPN, brand), Enhanced Ecommerce, OG price/currency, noindex on cart/checkout/account.</li> <li><strong>Easy Digital Downloads</strong> integration.</li> <li><strong>Internal linking suggestions</strong>.</li> <li><a href="https://www.seopress.org/features/sitemaps/" rel="nofollow ugc"><strong>Video XML Sitemap</strong></a> with automatic YouTube discovery + **Google News sitemap**.</li> <li><a href="https://www.seopress.org/features/google-analytics/" rel="nofollow ugc"><strong>Google Analytics dashboard</strong></a>: Metrics inside WordPress, no context switching.</li> <li><strong>PageSpeed Insights &amp; Core Web Vitals</strong> reports.</li> <li><a href="https://www.seopress.org/features/htaccess-robots-txt/" rel="nofollow ugc"><strong>robots.txt &amp; .htaccess editor</strong></a>: Multisite / multidomain ready.</li> <li><strong>Custom RSS feed</strong> options.</li> <li><strong>Multilingual llms.txt</strong> with TranslatePress.</li> </ul> <p><a href="https://www.seopress.org/pricing/" rel="nofollow ugc"><strong>Get SEOPress PRO <span aria-hidden="true" class="wp-exclude-emoji">→</span></strong></a></p> <h3>SEOPress Insights: Track rankings &amp; backlinks inside WordPress</h3> <ul> <li><strong>Keyword rank tracker</strong>: 52 Google Search locations.</li> <li>Track <strong>50 keywords/site daily</strong>.</li> <li><strong>Competitor tracking</strong>: See who outranks you.</li> <li><strong>Backlinks</strong> monitored weekly.</li> <li><strong>Google Trends</strong>: Find new content angles.</li> <li><strong>Lifetime data access</strong>: Export to CSV / PDF / Excel.</li> <li><strong>Email &amp; Slack alerts</strong>.</li> </ul> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/p6v9Jd5lRIU?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <p><a href="https://www.seopress.org/pricing/" rel="nofollow ugc"><strong>Get SEOPress Insights <span aria-hidden="true" class="wp-exclude-emoji">→</span></strong></a></p> <h3>WooCommerce &amp; EDD SEO (SEOPress PRO)</h3> <ul> <li>Product schema with global identifiers (GTIN, MPN, brand).</li> <li>OG price &amp; currency for richer social shares.</li> <li>XML sitemaps for products, including image galleries.</li> <li>Centralized noindex for cart/checkout/account/thank-you pages.</li> <li>Removes WooCommerce/EDD generator meta tag.</li> <li>Manual or automatic JSON-LD product schemas.</li> <li>Breadcrumbs with WooCommerce support.</li> <li>Global dynamic tags for titles &amp; meta descriptions.</li> <li>Google Enhanced Ecommerce: purchases, product views, cart events.</li> </ul> <p><a href="https://www.seopress.org/pricing/" rel="nofollow ugc"><strong>Boost your store&#8217;s SEO <span aria-hidden="true" class="wp-exclude-emoji">→</span></strong></a></p> <h3>Universal SEO metabox: works with every editor</h3> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/sf0ocG7vQMM?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <p>Edit your SEO directly inside Gutenberg, Elementor, Divi, Bricks, Oxygen, Breakdance, WPBakery, Avada, Kadence, WP Fusion. <strong>No more back-and-forth</strong> between page builder and WordPress admin.</p> <h3>Built for developers</h3> <ul> <li><strong>Hundreds of hooks</strong>: <a href="https://www.seopress.org/support/hooks/" rel="nofollow ugc">Browse the hooks reference</a>.</li> <li><strong>REST API</strong>: Power headless and static sites. <a href="https://www.seopress.org/support/guides/get-started-with-the-seopress-rest-api/" rel="nofollow ugc">Get started</a>.</li> <li><strong>WP-CLI commands</strong>: Automate everything. <a href="https://www.seopress.org/support/guides/seopress-wp-cli/" rel="nofollow ugc">CLI reference</a>.</li> <li><strong>13+ new dev hooks in 9.8</strong>.</li> </ul> <h3>From the same team</h3> <p><a href="https://wordpress.org/plugins/mailerpress/" rel="ugc">Try MailerPress, the best email marketing plugin for WordPress</a></p>
WordPress Plugin DirectoryWordPress Plugin Directory
19.4M