Medium severity6.4NVD Advisory· Published Sep 2, 2026
CVE-2026-75134
CVE-2026-75134
Description
SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist that explicitly permits the onload event handler on iframe elements. Attackers can store crafted JavaScript payloads in post content that execute when the affected post is viewed or previewed by higher-privileged users, potentially leading to privilege escalation or account compromise.
Affected products
1- Range: <=1.12.5
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.