Impact
The SEOPress AI SEO Plugin contains a stored XSS flaw where an attacker can inject arbitrary JavaScript into the Author Display Name field. Because the plugin does not sanitize or escape output, the malicious script becomes part of the page markup. When a visitor views a page that displays the author name—typically inside a tracking script for Google Analytics 4 or Matomo—the injected code executes in the visitor’s browser. This can lead to session hijacking, credential theft, or malicious content delivery to unsuspecting users.
Affected Systems
The vulnerability affects all releases of SEOPress – AI SEO Plugin & On‑site SEO up to and including version 10.2, supplied by rainbowgeek. Users of these versions should verify the plugin version installed in their WordPress installation.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity level. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw without authentication, provided they can publish public singular content such as forum posts. The presence of the 'Track Authors' custom dimension must be configured for the injection to surface in the tracking script. If successfully executed, the XSS can compromise confidentiality, integrity, and availability for site visitors, making timely remediation critical.
OpenCVE Enrichment