The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform any authorisation check on one of its REST API routes and disables HTML sanitisation before saving the post, allowing unauthenticated attackers to create administrator-attributed published posts containing arbitrary web scripts that execute in the browser of any visitor, including administrators (Stored XSS).
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-06 07:16
Updated : 2026-08-26 16:31
NVD link : CVE-2026-11588
Mitre link : CVE-2026-11588
CVE.ORG link : CVE-2026-11588
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
