rootpwn

high · CVSS v3 7.2 · EPSS 0.00236

CVE-2026-96564

The SEOPress AI SEO plugin for WordPress is vulnerable to stored XSS via the Author Display Name field in all versions up to 10.2. Unauthent

Overview

The SEOPress AI SEO plugin for WordPress is vulnerable to stored XSS via the Author Display Name field in all versions up to 10.2. Unauthenticated attackers can inject scripts that execute when users view pages containing the malicious author name. This flaw requires the plugin's Track Authors feature to be enabled and public content to be published.

Description

The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Author Display Name in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the 'Track Authors' custom dimension to be configured in the plugin's Google Analytics 4 or Matomo settings, and the attacker must be able to publish public singular content (e.g., via bbPress forum topics) so that the injected display name is rendered in the tracking script.

Impact

Confidentiality: malicious scripts can exfiltrate data or perform actions on behalf of users. Integrity: injected code can alter page content or redirect users. Availability: not directly impacted. Defenders: site administrators, WordPress users, plugin developers.

Remediation

Update SEOPress to version 10.3 or later. If updating is not possible, disable the Track Authors custom dimension or remove the plugin. Ensure author display names are properly sanitized or escape output. Restrict public content publishing or limit to authenticated users.

Risk context

High severity (CVSS 7.2) with a low EPSS of 0.00236 indicates a low likelihood but high impact if exploited. Defenders should prioritize patching promptly.

Affected products

  • SEOPress AI SEO Plugin
  • SEOPress SEO Plugin
  • WordPress SEOPress 10.2

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.2
CVSS v4
—
EPSS
0.00236

XSS WordPress SEOPress Stored XSS Plugin High Severity Mitigation

← All CVEs