Google SEO Pressor Snippet <= 2.0 - Cross-Site Request Forgery
medium
The Google SEO Pressor for Rich snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can...
- CVSS:
- 4.3
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2025
CVE-2025-31775 on NVD →
Google SEO Pressor for Rich snippets [google-seo-author-snippets] <= 2.0 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in smackcoders Google SEO Pressor Snippet allows Cross Site Request Forgery. This issue affects Google SEO Pressor Snippet: from n/a through 2.0.
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2025
CVE-2025-31775 on NVD →
Google SEO Pressor Snippet <= 2.0 - Missing Authorization
medium
The Google SEO Pressor for Rich snippets plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 31, 2025
CVE-2025-31530 on NVD →
Google SEO Pressor for Rich snippets [google-seo-author-snippets] <= 2.0 (unfixed)
unknown
[en] Missing Authorization vulnerability in smackcoders Google SEO Pressor Snippet allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Google SEO Pressor Snippet: from n/a through 2.0.
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 31, 2025
CVE-2025-31530 on NVD →
Google SEO Pressor for Rich snippets <= 1.2.2 - Cross-Site Scripting
medium
The Google SEO Pressor for Rich snippets plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.7
- Disclosed:
- Apr 21, 2016
Google SEO Pressor for Rich snippets [google-seo-author-snippets] < 1.2.7
unknown
This plugin is prone to a reflected cross site scripting vulnerability, because these parameters are not sanitized: "Address Region", "Longitude", "Latitude", "Event type", "Offer aggregate", "Low Price", "High Price", "Offer Url", "Price", "Events Website", "Offer Quantity", "Price valid Until", "Tickets currency", "...
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.7
- Disclosed:
- Apr 21, 2016
Google SEO Pressor for Rich snippets [google-seo-author-snippets] < 1.2.7
unknown
The Google SEO Pressor for Rich snippets plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.7
- Disclosed:
- Apr 21, 2016
Google SEO Pressor for Rich snippets [google-seo-author-snippets] < 1.2.7
unknown
The Google SEO Pressor for Rich snippets WordPress plugin was affected by a Reflected Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.7
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database