Stored XSS Vulnerability in DELUCKS SEO by DELUCKS
CVE-2025-53570

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2025

What is CVE-2025-53570?

The DELUCKS SEO plugin for WordPress has a vulnerability that allows attackers to execute arbitrary JavaScript in the context of the user’s browser. This Stored XSS vulnerability can be exploited when the plugin improperly handles user input during page generation, potentially allowing malicious actors to deliver harmful scripts to users. This issue affects all versions of DELUCKS SEO up to 2.7.0, exposing users to security risks. To mitigate this threat, users are advised to update to the latest version or apply appropriate security measures.

Affected Version(s)

DELUCKS SEO <= 2.7.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ (Patchstack Alliance)
.