Description
The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Author Display Name in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the 'Track Authors' custom dimension to be configured in the plugin's Google Analytics 4 or Matomo settings, and the attacker must be able to publish public singular content (e.g., via bbPress forum topics) so that the injected display name is rendered in the tracking script.
Published: 2026-10-03
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (XSS) allowing arbitrary script execution in the browser for site visitors
Action: Immediate Update
AI Analysis

Impact

The SEOPress AI SEO Plugin contains a stored XSS flaw where an attacker can inject arbitrary JavaScript into the Author Display Name field. Because the plugin does not sanitize or escape output, the malicious script becomes part of the page markup. When a visitor views a page that displays the author name—typically inside a tracking script for Google Analytics 4 or Matomo—the injected code executes in the visitor’s browser. This can lead to session hijacking, credential theft, or malicious content delivery to unsuspecting users.

Affected Systems

The vulnerability affects all releases of SEOPress – AI SEO Plugin & On‑site SEO up to and including version 10.2, supplied by rainbowgeek. Users of these versions should verify the plugin version installed in their WordPress installation.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity level. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw without authentication, provided they can publish public singular content such as forum posts. The presence of the 'Track Authors' custom dimension must be configured for the injection to surface in the tracking script. If successfully executed, the XSS can compromise confidentiality, integrity, and availability for site visitors, making timely remediation critical.

Generated by OpenCVE AI on October 3, 2026 at 06:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SEOPress to the latest available release (10.3 or later) that addresses the stored XSS flaw.
  • If an upgrade cannot be performed immediately, disable the 'Track Authors' custom dimension in the plugin’s Google Analytics or Matomo settings to prevent the injected script from rendering.
  • Surround any existing author display names with safe content by logging in as an administrator and removing embedded script tags or resetting the display name to a benign value.

Generated by OpenCVE AI on October 3, 2026 at 06:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Author Display Name in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the 'Track Authors' custom dimension to be configured in the plugin's Google Analytics 4 or Matomo settings, and the attacker must be able to publish public singular content (e.g., via bbPress forum topics) so that the injected display name is rendered in the tracking script.
Title SEOPress <= 10.2 - Unauthenticated Stored Cross-Site Scripting via Author Display Name
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:44.878Z

Reserved: 2026-09-23T13:18:39.398Z

Link: CVE-2026-96564

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:22.762Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:47.607

Modified: 2026-10-03T16:16:47.050

Link: CVE-2026-96564

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T06:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')