Unauthenticated Cross-Site Scripting in SEO Redirection by WordPress
CVE-2026-52702
7.1HIGH
What is CVE-2026-52702?
The SEO Redirection plugin for WordPress versions up to 9.17 is prone to an unauthenticated Cross-Site Scripting (XSS) vulnerability. This flaw allows attackers to inject malicious scripts into web pages viewed by users, potentially compromising their data and web application integrity. As a result, it is essential for site administrators to update to the latest plugin version to mitigate this security risk.
Affected Version(s)
SEO Redirection <= 9.17