CVE-2026-75134: SEOWriting WordPress Plugin 1.12.5 Stored XSS via iframe onload

Published Sep 2, 2026
·
Updated

SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist that explicitly permits the onload event handler on iframe elements. Attackers can store crafted JavaScript payloads in post content that execute when the affected post is viewed or previewed by higher-privileged users, potentially leading to privilege escalation or account compromise.

Affected Software

1 affected component
SEOWriting WordPress Plugin<=1.12.5

Event History

Sep 2, 2026
CVE Published
via MITRE·07:17 PM
Data Sourced
via MITRE·07:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which users can exploit this issue, and who is at risk from the payload?

An authenticated user with the Contributor role can store the malicious content. The payload executes when an affected post is viewed or previewed by a higher-privileged user, placing those users at risk of account compromise or privilege escalation.

2

Which plugin versions are affected?

The issue affects SEOWriting for WordPress through version 1.12.5. No fixed version is identified in the available information.

3

What content should be reviewed for signs of exploitation?

Review post content created or edited by contributors for iframe elements carrying an onload event handler. The vulnerability relies on storing JavaScript payloads in post content through iframe onload.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203