PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75134 SEOWriting CVE debrief

The SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist that explicitly permits the onload event handler on iframe elements. This vulnerability can lead to potential privilege escalation or account compromise. WordPress administrators, security teams, and users with contributor privileges should be aware of this vulnerability and take defensive actions to prevent potential attacks.

Vendor
SEOWriting
Product
Unknown
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-02
Original CVE updated
2026-09-03
Advisory published
2026-09-02
Advisory updated
2026-09-03

Who should care

WordPress administrators, security teams, and users with contributor privileges should be aware of this vulnerability and take defensive actions to prevent potential privilege escalation or account compromise. They should review and update their installations to prevent exploitation of this vulnerability. Additionally, security teams should monitor for suspicious post content changes and implement compensating controls such as Web Application Firewalls to mitigate the risk of this vulnerability. Users with contributor privileges should be cautious when creating or editing post content to avoid injecting malicious JavaScript code. Furthermore, it is essential for organizations to have incident response plans in place in case of a successful exploitation of this vulnerability. Regular security audits and penetration testing can also help identify and address potential vulnerabilities before they can be exploited. By taking these steps, organizations can reduce the risk of exploitation and protect their systems from potential attacks. Finally, staying informed about the latest security updates and patches can help prevent exploitation of known vulnerabilities like this one. This includes regularly reviewing and updating software, plugins, and themes to ensure they are up-to-date and secure. By prioritizing security and taking proactive measures, organizations can minimize the risk of exploitation and protect their systems from potential threats. The vulnerability can be mitigated by applying the recommended actions below. The actions below provide guidance on how to address the vulnerability and prevent exploitation. By following these steps, organizations can reduce the risk of exploitation and protect their systems from potential attacks. The recommended actions are designed to help organizations take proactive measures to prevent exploitation of this vulnerability. By implementing these actions, organizations can minimize the risk of exploitation and protect their systems from potential threats. The actions are intended to provide guidance on how to address the vulnerability and prevent exploitation. They are designed to help organizations take proactive steps.

Technical summary

The SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist that explicitly permits the onload event handler on iframe elements. Attackers can store crafted JavaScript payloads in post content that execute when the affected post is viewed or previewed by higher-privileged users, potentially leading to privilege escalation or account compromise.

Defensive priority

Medium-priority defensive actions are recommended due to the potential for privilege escalation or account compromise via stored cross-site scripting.

Recommended defensive actions

  • Inventory and triage of WordPress installations with the SEOWriting plugin
  • Upgrade to a patched version of the SEOWriting plugin
  • Implement compensating controls such as Web Application Firewalls
  • Monitor for suspicious post content changes
  • Restrict contributor privileges

Evidence notes

The SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability. Attackers can store crafted JavaScript payloads in post content that execute when the affected post is viewed or previewed by higher-privileged users. Evidence is based on a permissive KSES allowlist that explicitly permits the onload event handler on iframe elements.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75134 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75134

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75134 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75134

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.