high · CVSS v3 7.2 · EPSS 0.00236
CVE-2026-96564
The SEOPress AI SEO plugin for WordPress is vulnerable to stored XSS via the Author Display Name field in all versions up to 10.2. Unauthent
Overview
The SEOPress AI SEO plugin for WordPress is vulnerable to stored XSS via the Author Display Name field in all versions up to 10.2. Unauthenticated attackers can inject scripts that execute when users view pages containing the malicious author name. This flaw requires the plugin's Track Authors feature to be enabled and public content to be published.
Description
The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Author Display Name in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the 'Track Authors' custom dimension to be configured in the plugin's Google Analytics 4 or Matomo settings, and the attacker must be able to publish public singular content (e.g., via bbPress forum topics) so that the injected display name is rendered in the tracking script.
Impact
Confidentiality: malicious scripts can exfiltrate data or perform actions on behalf of users. Integrity: injected code can alter page content or redirect users. Availability: not directly impacted. Defenders: site administrators, WordPress users, plugin developers.
Remediation
Update SEOPress to version 10.3 or later. If updating is not possible, disable the Track Authors custom dimension or remove the plugin. Ensure author display names are properly sanitized or escape output. Restrict public content publishing or limit to authenticated users.
Risk context
High severity (CVSS 7.2) with a low EPSS of 0.00236 indicates a low likelihood but high impact if exploited. Defenders should prioritize patching promptly.
Affected products
- SEOPress AI SEO Plugin
- SEOPress SEO Plugin
- WordPress SEOPress 10.2
Scores
- Severity
- high
- CVSS v2
- 6.4
- CVSS v3
- 7.2
- CVSS v4
- —
- EPSS
- 0.00236