Vulnerability  ·  2026-10-05

SEOPress AI SEO plugin: stored XSS via Author Display Name (unauthenticated) plus stored XSS via GA matomo id

VulnerabilityMedium impactGlobalCVE-2026-96564
NVD published CVE-2026-96564 (CVSS 7.2) and the lower-severity CVE-2026-101357 on 2026-10-03 for stored XSS in the SEOPress AI SEO plugin up to 10.2, one exploitable by unauthenticated attackers via the author display name and one authenticated via a Matomo id option.
Stored XSS on an AI SEO plugin runs in the admin/visitor browser and can be used to hijack sessions or inject content on sites that rely on the plugin's AI SEO features. Niche but catalogued and exploitable; keep it on the triage list.
Stored cross-site scripting via the author display name (insufficient input sanitization/output escaping), executed in the browsers of anyone viewing pages where the plugin renders it; a separate stored XSS via the 'seopress_google_analytics_matomo_id' parameter (CVE-2026-101357) requires authenticated access.
SEOPress - AI SEO Plugin & On-site SEO WordPress plugin <= 10.2
Update SEOPress beyond 10.2 once patched. References: https://plugins.trac.wordpress.org/browser/wp-seopress/tags/10.2/inc/functions/options-google-analytics.php#L635 and Sanitize.php#L183
NVD CVE-2026-96564NVD CVE-2026-101357
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →