CVE-2026-75134
Last modified
CVE-2026-75134 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist that explicitly permits the onload event handler on iframe elements. Attackers can store crafted JavaScript payloads in post content that execute when the affected post is viewed or previewed by higher-privileged users, potentially leading to privilege escalation or account compromise.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist that explicitly permits the onload event handler on iframe elements. Attackers can store crafted JavaScript payloads in post content that execute when the affected post is viewed or previewed by higher-privileged users, potentially leading to privilege escalation or account compromise.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| SEOWriting | SEOWriting | <= 1.12.5 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-75134?
How severe is CVE-2026-75134?
How do I fix CVE-2026-75134?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-75126PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contain…4.9
- CVE-2026-7513A vulnerability has been found in UTT HiPER 1200GW up to 2.5…8.8
- CVE-2026-75130Context7 through 2.1.2 contains a prompt injection vulnerabi…9
- CVE-2026-75131NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contain…7.8
- CVE-2026-75132WAPT Server versions 2.6.1.17834 and earlier contains a SQL …6.5
- CVE-2026-75133Keep Backup Daily plugin for WordPress before 2.1.4 contains…7.5
- CVE-2026-75135UpSignOn for Windows before 7.19.0 contains a sensitive data…6.1
- CVE-2026-75136UpSignOn for Windows before 7.19.0 contains an insecure cred…6.1
- CVE-2026-75137UpSignOn for Windows before 7.19.0 contains a sensitive data…6.1
- CVE-2026-7514GitLab has remediated an issue in GitLab CE/EE affecting all…4.3
- CVE-2026-75140jsoup through 1.23.2, fixed in commit 862ba2f, contains an u…7.5
- CVE-2026-75141FFmpeg before commit acf5d7c contains a heap buffer overflow…7.8
Are you affected by CVE-2026-75134?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
