Executive brief
Smart SEO Tool is a WordPress plugin used to optimize website search engine rankings. A security vulnerability allows users with 'Contributor' level access to inject malicious scripts into the website. If a site administrator views the affected content, these scripts could allow an attacker to redirect visitors to malicious sites, display unauthorized advertisements, or perform actions on behalf of the administrator.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in the Smart SEO Tool plugin for WordPress (versions <= 4.1.2) due to improper neutralization of input during web page generation (CWE-79). The vulnerability requires 'Contributor' level privileges to inject malicious payloads. Successful exploitation occurs when a privileged user (such as an Administrator) interacts with the affected page or content, leading to the execution of arbitrary JavaScript in the context of their session. This can result in session hijacking or unauthorized site modifications. As of the advisory date, no official patch has been released.
Affected products
- wbolt.com Smart SEO Tool <= 4.1.2
Timeline
- 2026-06-12: other: Reported by researcher Ananda Dhakal
- 2026-07-23: disclosed: Vulnerability published by Patchstack and NVD