WordPress plugins enhance website functionality, but they can also introduce security vulnerabilities. One such vulnerability has been discovered in the SEOPress – On-site SEO plugin, affecting over 300,000 active installations. This vulnerability, identified as CVE-2024-4899, allows contributors to exploit a Stored XSS (Cross-Site Scripting) flaw, potentially leading to the creation of unauthorized admin accounts.
CVE-2024-4899 – SEOPress – On-site SEO – Stored XSS to Admin Account Creation (Contributor+) – POC
![CVE-2024-4899 – SEOPress – On-site SEO – Stored XSS to Admin Account Creation (Contributor+) – POC CVE-2024-4899 – SEOPress – On-site SEO – Stored XSS to Admin Account Creation (Contributor+) – POC](https://research.cleantalk.org/wp-content/uploads/2023/10/New_1_not_safe-1.png)