MEDIUM
SEOWriting
CVE published 2026-09-02
CVE-2026-75134
The SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist that explicitly permits the onload event handler on iframe elements. This vulnerability can lead to potential privilege escalation or account compromise. WordPress administrators, secu [truncated]