PT-2026-104415 · WordPress · All In One Seo
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
All in One SEO versions prior to 5.0.2.1
Description
Unauthenticated users can execute arbitrary shortcodes registered on the site because the plugin fails to correctly determine which shortcodes are present in content derived from user input before stripping them. On sites upgraded from older versions, the protection is disabled entirely, allowing the issue to be triggered without crafted input. This affects over 3 million WordPress sites.
Recommendations
Update to version 5.0.2.1 or later.
Audit all registered shortcodes to understand the potential risk surface.
Check untrusted-input fields, such as comments and submissions, for shortcode-syntax patterns.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
All In One Seo