Stored Cross-Site Scripting Vulnerability in SEOWriting Plugin for WordPress
CVE-2026-75134

5.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 September 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-75134?

The SEOWriting plugin for WordPress, up to version 1.12.5, contains a stored cross-site scripting vulnerability. Authenticated contributors can exploit this issue by injecting malicious JavaScript into post content. The vulnerability arises from an overly permissive KSES allowlist that allows the onload event handler on iframe elements. Attackers can craft and store JavaScript payloads that execute when affected posts are viewed or previewed, particularly impacting higher-privileged users. This could lead to privilege escalation or account compromise, posing significant security risks.

Affected Version(s)

SEOWriting 0 <= 1.12.5

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Elymaro (Aurélien Bourdois)
.