Junglewise Threat Intelligence

CVE-2026-85305: SEOPress Server-Side Request Forgery in import functionality

CVE-2026-85305 · Severity: medium · CVSS 5.4 · Published 2026-09-03

Executive brief

SEOPress is a popular WordPress plugin that provides SEO optimization and configuration features for WordPress sites. A Server-Side Request Forgery vulnerability allows authenticated attackers to make the server connect to internal systems and exfiltrate sensitive data from behind corporate firewalls or access internal services.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in SEOPress versions through 10.1. The vulnerability requires contributor-level or higher privileges to exploit and necessitates user interaction (clicking a malicious link or visiting a crafted page). Successful exploitation enables attackers to make arbitrary server-side requests to internal systems, potentially bypassing network security controls and exfiltrating sensitive data from internal resources or services inaccessible from the internet. The issue has been patched in version 10.2 or later.

Affected products

  • SEOPress SEOPress through 10.1

Timeline

  • 2026-08-27: disclosed
  • 2026-09-03: advisory
  • 2026-09-03: patched: patched in version 10.2

References