VYPR
Medium severity6.4NVD Advisory· Published Aug 16, 2021· Updated Jun 17, 2026

CVE-2021-34641

CVE-2021-34641

Description

The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/src/Actions/Api/TitleDescriptionMeta.php file which allows authenticated attackers to inject arbitrary web scripts, in versions 5.0.0 - 5.0.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Seopress/Seopress2 versions
    cpe:2.3:a:seopress:seopress:*:*:*:*:*:wordpress:*:*+ 1 more
    • cpe:2.3:a:seopress:seopress:*:*:*:*:*:wordpress:*:*range: >=5.0.0,<5.0.4
    • (no CPE)range: 5.0.0
  • Range: 5.0.0 - 5.0.3

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.