CVE WATCH / VULNERABILITY DETAIL
CVE-2026-96564
HIGHCVSS 7.2NVD feed
Published 3 October 2026 · tracked since 3 October 2026
Description
The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Author Display Name in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-94505 HIGH 8.1
- CVE-2026-96267 HIGH 7.5
- CVE-2026-75028 HIGH 7.5
- CVE-2026-87115 CRITICAL 9.1
- CVE-2026-93889 HIGH 7.2
- CVE-2026-18443 HIGH 8.8
- CVE-2026-100157 MEDIUM 6.5
- CVE-2026-97341 HIGH 7.2
- CVE-2026-96650 HIGH 7.2
- CVE-2026-97337 HIGH 7.5