WP Vulnerability WatchVulnerability data as of September 7, 2026

Vulnerability alerts / September 2, 2026

Vulnerability in SEOWriting — CVE-2026-75134

MediumSeverity
CVSS 5.1
0.2%Estimated exploit probability
EPSS
30,000+ sitesInstalls
Not publishedFixed in

What to do now

No fix has been published yet. Consider disabling SEOWriting for now, or moving to an alternative.

Affected versions

  • Everything up to and including 1.12.5

Affected: SEOWriting (plugin, seowriting)

Check: The plugin on wordpress.org / Our record for SEOWriting

What the vulnerability is

SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist that explicitly permits the onload event handler on iframe elements. Attackers can store crafted JavaScript payloads in post content that execute when the affected post is viewed or previewed by higher-privileged users, potentially leading to privilege escalation or account compromise.

This description is reproduced verbatim from the public vulnerability record.

Sources

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts