Impact
The SEOPress plugin stores the value supplied to the seopress_google_analytics_matomo_id parameter without adequate sanitization. An authenticated user with a Subscriber role or higher who has been granted the Analytics management capability can inject arbitrary JavaScript into the stored option. When a visitor loads a page that displays the stored value, the injected script executes in the visitor’s browser, allowing attackers to deface pages, exfiltrate credentials, or redirect users to malicious sites.
Affected Systems
WordPress sites that run the SEOPress – AI SEO Plugin & On‑site SEO by rainbowgeek with versions up to and including 10.2. The flaw is exploitable for any user who has the Analytics management capability assigned to the Subscriber role in the plugin’s Advanced > Security settings.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate risk. EPSS is not available, so no probability estimate is supplied, and the vulnerability is not listed in CISA’s KEV catalog. Attackers must be authenticated as a Subscriber or higher and must have the plugin capability that allows them to edit analytics settings. The vulnerability does not provide remote code execution but enables XSS by forcing the script to run in the context of site visitors when the stored value is displayed.
OpenCVE Enrichment