Premium SEO Pack <= 3.3.2 - Authenticated (Subscriber+) SQL Injection
medium
The Premium SEO Pack plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and...
- CVSS:
- 6.5
- Affected:
- up to 3.3.2
- Fix:
- No patched version reported
- Disclosed:
- Jul 8, 2025
CVE-2025-31044 on NVD →
Premium SEO Pack <= 1.6.001 - Authenticated (Contributor+) SQL Injection
medium
The Premium SEO Pack plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.001 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access...
- CVSS:
- 6.5
- Affected:
- up to 1.6.001
- Fixed in:
- 1.6.002
- Disclosed:
- Oct 24, 2024
CVE-2024-50465 on NVD →
Premium SEO Pack – WP SEO Plugin <= 1.6.002 - Unauthenticated Information Exposure
medium
The Premium SEO Pack – WP SEO Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.002. This makes it possible for unauthenticated attackers to view limited information from password protected posts through the social meta data.
- CVSS:
- 5.3
- Affected:
- up to 1.6.002
- Fix:
- No patched version reported
- Disclosed:
- Aug 28, 2024
CVE-2024-3679 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database