Impact
SEOWriting plugin for WordPress up to version 1.12.5 contains a stored cross‑site scripting flaw that allows an authenticated contributor to insert malicious JavaScript through an iframe onload event handler. The plugin’s KSES allowlist mistakenly permits this attribute, letting the script execute whenever a higher‑privileged user views or previews the affected post, which can lead to privilege escalation or account compromise.
Affected Systems
WordPress sites that have installed the SEOWriting plugin version 1.12.5 or earlier. The vulnerability is tied specifically to the SEOWriting plugin and does not affect other WordPress components unless the plugin’s allowlist is also used elsewhere.
Risk and Exploitability
The CVSS score of 5.1 places the vulnerability in the medium range, and the EPSS score is not available, so the likelihood of exploitation remains uncertain. The flaw is not listed in CISA’s KEV catalog. Attackers require authenticated contributor access to insert the payload, after which it persists in stored content and triggers when viewed by users with higher privileges. Because of the stored nature of the flaw, the risk is ongoing until the issue is fixed or mitigated.
OpenCVE Enrichment