CVE-2023-1669: Seopress
High severity, CVSS 7.2. EPSS: 17.7% chance of exploitation in the next 30 days.
The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
Affected products
- Seopress Seopress: before 6.5.0.3 (fixed in 6.5.0.3)
Published 2023-05-02. Last modified 2026-06-17.