Stored Cross-Site Scripting Vulnerability in Sentence To SEO Plugin for WordPress
CVE-2026-4142
4.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 April 2026
What is CVE-2026-4142?
The Sentence To SEO plugin for WordPress has a vulnerability that allows authenticated attackers with administrator rights to inject arbitrary HTML and JavaScript through the 'Permanent keywords' field. This occurs due to a lack of input sanitization and proper output escaping when storing user inputs in the WordPress options table. As a result, an attacker can manipulate the textarea element's content, leading to potential execution of malicious scripts whenever the plugin's settings page is accessed.
Affected Version(s)
Sentence To SEO (keywords, description and tags) 0 <= 1.0