Stored Cross-Site Scripting Vulnerability in SEOWriting Plugin for WordPress
CVE-2026-75134
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 2 September 2026
Badges
What is CVE-2026-75134?
The SEOWriting plugin for WordPress, up to version 1.12.5, contains a stored cross-site scripting vulnerability. Authenticated contributors can exploit this issue by injecting malicious JavaScript into post content. The vulnerability arises from an overly permissive KSES allowlist that allows the onload event handler on iframe elements. Attackers can craft and store JavaScript payloads that execute when affected posts are viewed or previewed, particularly impacting higher-privileged users. This could lead to privilege escalation or account compromise, posing significant security risks.
Affected Version(s)
SEOWriting 0 <= 1.12.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved