What happened
NVD published CVE-2026-96564 (CVSS 7.2) and the lower-severity CVE-2026-101357 on 2026-10-03 for stored XSS in the SEOPress AI SEO plugin up to 10.2, one exploitable by unauthenticated attackers via the author display name and one authenticated via a Matomo id option.
Why it matters
Stored XSS on an AI SEO plugin runs in the admin/visitor browser and can be used to hijack sessions or inject content on sites that rely on the plugin's AI SEO features. Niche but catalogued and exploitable; keep it on the triage list.
Attack vector
Stored cross-site scripting via the author display name (insufficient input sanitization/output escaping), executed in the browsers of anyone viewing pages where the plugin renders it; a separate stored XSS via the 'seopress_google_analytics_matomo_id' parameter (CVE-2026-101357) requires authenticated access.
Affected systems
SEOPress - AI SEO Plugin & On-site SEO WordPress plugin <= 10.2
Mitigation
Update SEOPress beyond 10.2 once patched. References: https://plugins.trac.wordpress.org/browser/wp-seopress/tags/10.2/inc/functions/options-google-analytics.php#L635 and Sanitize.php#L183