PT-2026-104509 · WordPress · Seopress
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress versions prior to 10.3
Description
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping of the author display name. Unauthenticated attackers can inject arbitrary web scripts into pages that execute when a user accesses them. This requires the
Track Authors custom dimension to be enabled in the Google Analytics 4 or Matomo settings, and the attacker must be able to publish public singular content, such as bbPress forum topics, to ensure the injected display name is rendered in the tracking script.Recommendations
Update the plugin to version 10.3 or later.
As a temporary mitigation, disable the
Track Authors custom dimension in the Google Analytics 4 or Matomo settings.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Seopress