The Simple SEO plugin for WordPress is vulnerable to attribute-based stored Cross-Site Scripting in versions up to, and including 1.7.91, due to insufficient sanitization or escaping on the SEO social and standard title parameters. This can be exploited by authenticated users with Contributor and above permissions to inject arbitrary web scripts into posts/pages that execute whenever an administrator access the page.
Metrics
Affected Vendors & Products
References
History
Fri, 31 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2022-09-06T17:18:55.000Z
Updated: 2025-01-31T18:51:59.157Z
Reserved: 2022-05-09T00:00:00.000Z
Link: CVE-2022-1628
Updated: 2024-08-03T00:10:03.751Z
Status : Modified
Published: 2022-09-06T18:15:10.423
Modified: 2024-11-21T06:41:07.740
Link: CVE-2022-1628
No data.