What is CVE-2026-11588?
The EONSR AEO Agent WordPress plugin (≤3.7.9) lacks authorization checks on a REST API route and disables HTML sanitization before saving posts. This allows unauthenticated attackers to create published posts attributed to an administrator, containing arbitrary web scripts. Users should immediately update the plugin or temporarily disable it.
Azərbaycanca: EONSR AEO Agent WordPress plaginində (≤3.7.9) REST API marşrutu üzərində avtorizasiya yoxlanışı aparılmır və HTML təmizlənməsi deaktiv edilir. Bu boşluq autentifikasiya olunmamış hücumçulara administrator atributlu, ixtiyari veb skriptləri ehtiva edən dərc olunmuş yazılar yaratmağa imkan verir. İstifadəçilər dərhal plagini ən son versiyaya yeniləməli və ya müvəqqəti olaraq deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the EONSR AEO Agent plugin are affected by CVE-2026-11588?
Versions up to and including 3.7.9 are affected.
What does this vulnerability allow an unauthenticated attacker to do?
It allows them to create published posts attributed to an administrator, containing arbitrary web scripts.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.