VYPR
Medium severity6.5NVD Advisory· Published Jun 3, 2024· Updated Apr 23, 2026

CVE-2024-34801

CVE-2024-34801

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mervin Praison Praison SEO WordPress seo-wordpress allows DOM-Based XSS.This issue affects Praison SEO WordPress: from n/a through <= 4.0.15.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

DOM-based XSS in Praison SEO WordPress plugin versions ≤4.0.15 allows attackers to inject malicious scripts via unsanitized input.

Vulnerability

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Praison SEO WordPress plugin (seo-wordpress) versions up to and including 4.0.15. The plugin fails to properly neutralize user-supplied input during web page generation, enabling script injection into the DOM of a victim's browser. The flaw resides in the client-side handling of data, likely within JavaScript that processes URL fragments or other DOM sources without sanitization.

Exploitation

An attacker can exploit this vulnerability by crafting a malicious URL containing a payload in a DOM-reachable parameter (e.g., a fragment identifier). The victim must click the crafted link while logged into the WordPress admin area or while the plugin's frontend scripts are active. No additional authentication or network position is required beyond luring the victim to the malicious link.

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser. This can lead to session hijacking, defacement, or theft of sensitive information such as authentication cookies or admin credentials. The attack is confined to the victim's browser session and does not directly compromise the server.

Mitigation

The vulnerability is fixed in version 5.0.6 of the Praison SEO plugin, as indicated by the plugin repository [1]. Users should update to the latest version immediately. No official workaround has been published; disabling the plugin until an update is applied is a temporary measure. The plugin is actively maintained, and the fix is available via the WordPress plugin directory.

References
  1. Praison AI SEO

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.