PatchSiren cyber security CVE debrief
CVE-2026-101357 rainbowgeek CVE debrief
The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'seopress_google_analytics_matomo_id' parameter in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Vendor
- rainbowgeek
- Product
- SEOPress – AI SEO Plugin & On-site SEO
- CVSS
- MEDIUM 4.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-03
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-03
- Advisory updated
- 2026-10-03
Who should care
WordPress administrators and security teams should assess exposure and prioritize remediation for installations using the SEOPress plugin, especially if subscriber-level access or higher has been delegated.
Why it matters
CVE-2026-101357 is a Stored Cross-Site Scripting vulnerability in the SEOPress WordPress plugin. Defenders should assess exposure, prioritize remediation, verify subscriber access, and monitor for suspicious activity.
- Authenticated attackers with subscriber-level access can inject arbitrary web scripts.
- Injected scripts execute when a user accesses an injected page.
- Requires verification of WordPress installations and SEOPress plugin versions.
- Remediation priority depends on the delegation of Analytics management capability to Subscriber roles.
Technical summary
The SEOPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'seopress_google_analytics_matomo_id' parameter. This requires an administrator to have delegated the Analytics management capability to the Subscriber role via the plugin's Advanced > Security settings. The vulnerability allows authenticated attackers with subscriber-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The plugin's insufficient input sanitization and output escaping enable this vulnerability.
Defensive priority
Assess exposure and prioritize remediation for WordPress installations using the SEOPress plugin, especially if subscriber-level access or higher has been delegated.
Recommended defensive actions
- Assess exposure: Review WordPress installations for SEOPress plugin usage and version.
- Prioritize remediation: Update SEOPress to a fixed version if available.
- Verify subscriber access: Review WordPress user roles and ensure subscriber-level access is properly managed.
- Monitor for suspicious activity: Keep an eye on WordPress site activity for potential exploitation attempts.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and references to source code. The vulnerability is a Stored Cross-Site Scripting via the 'seopress_google_analytics_matomo_id' parameter in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. The source code review indicates that the plugin does not properly sanitize user input, allowing attackers to inject malicious scripts. Defenders should verify the WordPress installations and 3
Sources and references
Verified primary and authoritative sources
-
CVE-2026-101357 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-101357
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-101357 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-101357
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wp-seopress/tags/10.2/inc/admin/sanitize/Sanitize.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wp-seopress/tags/10.2/inc/functions/options-matomo.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wp-seopress/tags/10.2/src/Actions/Api/Options/AnalyticsSettings.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.