Stored Cross-Site Scripting Vulnerability in SiteSEO Plugin for WordPress
CVE-2025-9277
6.4MEDIUM
What is CVE-2025-9277?
The SiteSEO – SEO Simplified plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability due to a flawed preg_replace expression. This issue arises from inadequate sanitization of user inputs and fails to properly escape outputs. As a result, authenticated users with Contributor-level access can exploit this vulnerability to inject malicious scripts into web pages, leading to execution of those scripts when other users access the compromised pages.
Affected Version(s)
SiteSEO – SEO Simplified * <= 1.2.7