PT-2026-84856 · WordPress · Seowriting
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SEOWriting plugin for WordPress versions prior to 1.12.6
Description
An issue exists where authenticated contributors can inject malicious JavaScript into post content. This is possible due to an overly permissive KSES allowlist—a security filter used by WordPress to sanitize HTML—that explicitly permits the
onload event handler on iframe elements. When a higher-privileged user views or previews the affected post, the stored JavaScript payload executes, which may result in account compromise or privilege escalation.Recommendations
Update the SEOWriting plugin for WordPress to version 1.12.6 or later.
Exploit
Fix
LPE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Seowriting