PatchSiren cyber security CVE debrief
CVE-2026-75134 SEOWriting CVE debrief
The SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist that explicitly permits the onload event handler on iframe elements. This vulnerability can lead to potential privilege escalation or account compromise. WordPress administrators, security teams, and users with contributor privileges should be aware of this vulnerability and take defensive actions to prevent potential attacks.
- Vendor
- SEOWriting
- Product
- Unknown
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-02
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-02
- Advisory updated
- 2026-09-03
Who should care
WordPress administrators, security teams, and users with contributor privileges should be aware of this vulnerability and take defensive actions to prevent potential privilege escalation or account compromise. They should review and update their installations to prevent exploitation of this vulnerability. Additionally, security teams should monitor for suspicious post content changes and implement compensating controls such as Web Application Firewalls to mitigate the risk of this vulnerability. Users with contributor privileges should be cautious when creating or editing post content to avoid injecting malicious JavaScript code. Furthermore, it is essential for organizations to have incident response plans in place in case of a successful exploitation of this vulnerability. Regular security audits and penetration testing can also help identify and address potential vulnerabilities before they can be exploited. By taking these steps, organizations can reduce the risk of exploitation and protect their systems from potential attacks. Finally, staying informed about the latest security updates and patches can help prevent exploitation of known vulnerabilities like this one. This includes regularly reviewing and updating software, plugins, and themes to ensure they are up-to-date and secure. By prioritizing security and taking proactive measures, organizations can minimize the risk of exploitation and protect their systems from potential threats. The vulnerability can be mitigated by applying the recommended actions below. The actions below provide guidance on how to address the vulnerability and prevent exploitation. By following these steps, organizations can reduce the risk of exploitation and protect their systems from potential attacks. The recommended actions are designed to help organizations take proactive measures to prevent exploitation of this vulnerability. By implementing these actions, organizations can minimize the risk of exploitation and protect their systems from potential threats. The actions are intended to provide guidance on how to address the vulnerability and prevent exploitation. They are designed to help organizations take proactive steps.
Technical summary
The SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist that explicitly permits the onload event handler on iframe elements. Attackers can store crafted JavaScript payloads in post content that execute when the affected post is viewed or previewed by higher-privileged users, potentially leading to privilege escalation or account compromise.
Defensive priority
Medium-priority defensive actions are recommended due to the potential for privilege escalation or account compromise via stored cross-site scripting.
Recommended defensive actions
- Inventory and triage of WordPress installations with the SEOWriting plugin
- Upgrade to a patched version of the SEOWriting plugin
- Implement compensating controls such as Web Application Firewalls
- Monitor for suspicious post content changes
- Restrict contributor privileges
Evidence notes
The SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability. Attackers can store crafted JavaScript payloads in post content that execute when the affected post is viewed or previewed by higher-privileged users. Evidence is based on a permissive KSES allowlist that explicitly permits the onload event handler on iframe elements.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75134 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75134
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75134 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75134
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Elymaro/CVE/blob/main/WordPress/CVE-2026-75134.md
-
Source reference
Unverified legacy reference
URL: https://wordpress.org/plugins/seowriting/
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/seowriting-wordpress-plugin-stored-xss-via-iframe-onload
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.