Stored Cross-Site Scripting in SEOPress Plugin for WordPress
CVE-2026-96564

7.2HIGH

What is CVE-2026-96564?

The SEOPress Plugin for WordPress is exposed to a vulnerability that allows unauthenticated attackers to inject malicious scripts via the Author Display Name. This issue arises from inadequate input validation and output escaping. For exploitation to occur, the 'Track Authors' feature needs to be enabled in either Google Analytics 4 or Matomo settings, and the attacker must have the ability to publish public content, like forum topics, where the malicious display name can trigger the scripts when users access the affected pages.

Affected Version(s)

SEOPress – AI SEO Plugin & On-site SEO 0 <= 10.2

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adrien Brunner
.