CVE-2026-101357: SEOPress <= 10.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'seopress_google_analytics_matomo_id' Parameter
The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'seopressgoogleanalyticsmatomoid' parameter in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires an administrator to have delegated the Analytics management capability to the Subscriber role via the plugin's Advanced > Security settings.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
In Advanced > Security settings, revoke or avoid delegating the Analytics management capability to the Subscriber role.
SEOPress – AI SEO Plugin & On-site SEO Analytics management capability delegation = do not delegate to Subscriber role
Event History
Frequently Asked Questions
Are sites using the default SEOPress role configuration exposed?
Not necessarily. Exploitation requires an administrator to have delegated the plugin's Analytics management capability to the Subscriber role through Advanced > Security settings.
What access does an attacker need?
The attacker must be able to authenticate to the WordPress site as a Subscriber or a higher-privileged user with the delegated Analytics management capability. They can then supply malicious script through the seopress_google_analytics_matomo_id parameter.
What is the likely impact if exploitation succeeds?
Injected scripts are stored and execute when a user visits a page containing the payload. This can expose or alter information available in that user's browser session, including when an administrator accesses the affected page.