Executive brief
The iRobots.txt SEO plugin for WordPress, which helps manage search engine crawler instructions, contains a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor clicks on a specially crafted link, the attacker could potentially hijack user sessions, redirect visitors to malicious websites, or deface the site. No official fix is currently available, so site owners should exercise caution when clicking external links related to their site management.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the iRobots.txt SEO plugin for WordPress (versions <= 1.1.2) due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into interacting with a specially crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized actions. As of the latest advisory, no official patch has been released by the developer.
Affected products
- iRobots.txt SEO Team iRobots.txt SEO <= 1.1.2
Timeline
- 2025-10-31: disclosed: Vulnerability reported by Skalucy
- 2026-01-20: advisory: Patchstack published advisory details
- 2026-06-15: advisory: CVE published in NVD