Stored Cross-Site Scripting in SEOPress Plugin for WordPress
CVE-2026-96564
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-96564?
The SEOPress Plugin for WordPress is exposed to a vulnerability that allows unauthenticated attackers to inject malicious scripts via the Author Display Name. This issue arises from inadequate input validation and output escaping. For exploitation to occur, the 'Track Authors' feature needs to be enabled in either Google Analytics 4 or Matomo settings, and the attacker must have the ability to publish public content, like forum topics, where the malicious display name can trigger the scripts when users access the affected pages.
Affected Version(s)
SEOPress β AI SEO Plugin & On-site SEO 0 <= 10.2