Vulnerabilities and security researches fordelucks-seo delucks-seo
Direction: ascendingJun 06, 2024
DELUCKS SEO # CVE-2019-25146
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 07, 2023
- Research Description
- The DELUCKS SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the saveSettings() function that had no capability checks in versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute whenever a victim accesses the page.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
DELUCKS SEO # CVE-2024-30538
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 09, 2024
- Research Description
- Missing Authorization vulnerability in DELUCKS GmbH DELUCKS SEO.This issue affects DELUCKS SEO: from n/a through 2.5.4.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
DELUCKS SEO # 63544f60dbd62bf3c6792e5d37b98841fe19ee6c
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 25, 2019
- Research Description
- DELUCKS SEO [delucks-seo] < 2.1.8 WordPress DELUCKS SEO plugin <= 2.1.7 - Unauthenticated Options Update vulnerability Unauthenticated Options Update vulnerability found in WordPress DELUCKS SEO plugin (versions <= 2.1.7).
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Dec 15, 2024
DELUCKS SEO # CVE-2024-54259
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 13, 2024
- Research Description
- Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DELUCKS GmbH DELUCKS SEO allows Path Traversal.This issue affects DELUCKS SEO: from n/a through 2.5.5.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
May 09, 2025
DELUCKS SEO # CVE-2025-47686
- CVE, Research URL
- Home page URL
- Application
- Date
- May 07, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DELUCKS DELUCKS SEO allows Stored XSS. This issue affects DELUCKS SEO: from n/a through 2.5.9.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Aug 07, 2025
DELUCKS SEO # CVE-2025-48165
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- DELUCKS SEO [delucks-seo] < 2.6.1 CVE-2025-48165
- Affected versions
-
Min -, max -.
- Status
-
vulnerable