PT-2026-84856 · WordPress · Seowriting

·

CVE-2026-75134

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SEOWriting plugin for WordPress versions prior to 1.12.6
Description An issue exists where authenticated contributors can inject malicious JavaScript into post content. This is possible due to an overly permissive KSES allowlist—a security filter used by WordPress to sanitize HTML—that explicitly permits the onload event handler on iframe elements. When a higher-privileged user views or previews the affected post, the stored JavaScript payload executes, which may result in account compromise or privilege escalation.
Recommendations Update the SEOWriting plugin for WordPress to version 1.12.6 or later.

Exploit

Fix

LPE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75134

Affected Products

Seowriting