PT-2026-104509 · WordPress · Seopress

·

CVE-2026-96564

·

Published

2026-10-03

·

Updated

2026-10-03

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress versions prior to 10.3
Description Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping of the author display name. Unauthenticated attackers can inject arbitrary web scripts into pages that execute when a user accesses them. This requires the Track Authors custom dimension to be enabled in the Google Analytics 4 or Matomo settings, and the attacker must be able to publish public singular content, such as bbPress forum topics, to ensure the injected display name is rendered in the tracking script.
Recommendations Update the plugin to version 10.3 or later. As a temporary mitigation, disable the Track Authors custom dimension in the Google Analytics 4 or Matomo settings.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96564

Affected Products

Seopress