Simple SEO [cds-simple-seo] < 2.0.32
unknown
[en] The Simple SEO WordPress plugin before 2.0.32 does not sanitise and escape some parameters when outputing them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.
- Affected:
- up to 2.0.32
- Fixed in:
- 2.0.32
- Disclosed:
- Oct 14, 2025
CVE-2025-10357 on NVD →
Simple SEO <= 2.0.31 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Simple SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 6.4
- Affected:
- up to 2.0.31
- Fixed in:
- 2.0.32
- Disclosed:
- Sep 23, 2025
CVE-2025-10357 on NVD →
Simple SEO [cds-simple-seo] < 2.0.26
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO plugin <= 2.0.25 versions.
- Affected:
- up to 2.0.26
- Fixed in:
- 2.0.26
- Disclosed:
- Oct 13, 2023
CVE-2023-45269 on NVD →
Simple SEO <= 2.0.25 - Cross-Site Request Forgery via multiple admin_post functions
medium
The Simple SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.25. This is due to missing or incorrect nonce validation on multiple admin_post functions. This makes it possible for unauthenticated attackers to import SEO content from other plugins as well as genera...
- CVSS:
- 5.4
- Affected:
- up to 2.0.25
- Fixed in:
- 2.0.26
- Disclosed:
- Oct 6, 2023
CVE-2023-45269 on NVD →
Simple SEO [cds-simple-seo] < 1.8.13
unknown
[en] Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO (WordPress plugin) plugin <= 1.8.12 versions.
- Affected:
- up to 1.8.13
- Fixed in:
- 1.8.13
- Disclosed:
- Nov 3, 2022
CVE-2022-36404 on NVD →
Simple SEO [cds-simple-seo] < 1.8.13
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO plugin <= 1.8.12 on WordPress allows attackers to create or delete sitemaps.
- Affected:
- up to 1.8.13
- Fixed in:
- 1.8.13
- Disclosed:
- Nov 3, 2022
CVE-2022-44627 on NVD →
Simple SEO <= 1.8.12 - Cross-Site Request Forgery to Sitemap Deletion/Creation
high
The Simple SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.12. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to create or delete sitemaps, via forged request granted they can trick a site administrato...
- CVSS:
- 8.8
- Affected:
- up to 1.8.12
- Fixed in:
- 1.8.13
- Disclosed:
- Oct 20, 2022
CVE-2022-36404 on NVD →
Simple SEO <= 1.8.12 - Cross-Site Request Forgery
high
The Simple SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.12. This is due to missing or incorrect nonce validation when managing sitemaps. This makes it possible for unauthenticated attackers to create or delete, via forged request granted they can trick a sit...
- CVSS:
- 8.8
- Affected:
- up to 1.8.12
- Fixed in:
- 1.8.13
- Disclosed:
- Oct 20, 2022
CVE-2022-44627 on NVD →
Simple SEO [cds-simple-seo] < 1.7.92
unknown
[en] The Simple SEO plugin for WordPress is vulnerable to attribute-based stored Cross-Site Scripting in versions up to, and including 1.7.91, due to insufficient sanitization or escaping on the SEO social and standard title parameters. This can be exploited by authenticated users with Contributor and above permissions...
- Affected:
- up to 1.7.92
- Fixed in:
- 1.7.92
- Disclosed:
- Sep 6, 2022
CVE-2022-1628 on NVD →
Simple SEO <= 1.7.91 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Simple SEO plugin for WordPress is vulnerable to attribute-based stored Cross-Site Scripting in versions up to, and including 1.7.91, due to insufficient sanitization or escaping on the SEO social and standard title parameters. This can be exploited by authenticated users with Contributor and above permissions to i...
- CVSS:
- 6.4
- Affected:
- up to 1.7.91
- Fixed in:
- 1.7.92
- Disclosed:
- Jul 29, 2022
CVE-2022-1628 on NVD →
Simple SEO <= 1.7.91 - Reflected Cross-Site Scripting
medium
The Simple SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in versions up to, and including, 1.7.91 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if the...
- CVSS:
- 6.1
- Affected:
- up to 1.7.91
- Fixed in:
- 1.7.92
- Disclosed:
- Jul 12, 2022
Simple SEO [cds-simple-seo] < 1.7.92
unknown
The Simple SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in versions up to, and including, 1.7.91 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if the...
- Affected:
- up to 1.7.92
- Fixed in:
- 1.7.92
- Disclosed:
- Jul 12, 2022
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database