SEOPress for MainWP
SEOPress for MainWP has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 8.1, and the most serious one scores 8.1 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is PHP Remote File Inclusion, behind 1 of the records (100%).
The one issue recorded for SEOPress for MainWP has a vendor fix available, so running the current release closes it.
All of these findings were reported by LVT-tholv2k. SEOPress for MainWP is installed on roughly 900 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-48298SEOPress for MainWP <= 1.4 - Unauthenticated Local File Inclusion
Read the full analysisVulnerability Records

SEOPress for MainWP
Author
Benjamin Denis
This is a free add-on for MainWP plugin. Features ✔ Quickly edit your global SEOPress settings: Titles and metas XML – HTML Sitemap Social Networks Analytics Instant Indexing Advanced Redirections / 404 (*) Structured data types (*) robots.txt (*) Local Business (*) Breadcrumbs (*) WooCommerce (*) Easy Digital Downloads (*) Google Search Console (*) Google News (*) URL rewriting (*) RSS feeds (*) White label (*) AI (*) (*SEOPress PRO required) ✔ Import / export your SEOPress configuration from a site to another in seconds. ✔ GDPR ready Requirements MainWP dashboard (>= 4.2.7) MainWP child plugin on at least 1 sub-site (>= 4.2.6) SEOPress Free (>= 5.9) installed and activated on the MainWP dashboard and at least 1 sub-site SEOPress PRO (>= 5.9, optional) installed and activated on the MainWP dashboard and at least 1 sub-site
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C