CVE-2023-1669: Seopress

High severity, CVSS 7.2. EPSS: 17.7% chance of exploitation in the next 30 days.

The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

Affected products

  • Seopress Seopress: before 6.5.0.3 (fixed in 6.5.0.3)

Published 2023-05-02. Last modified 2026-06-17.