PT-2026-104415 · WordPress · All In One Seo

·

CVE-2026-19856

·

Published

2026-10-02

·

Updated

2026-10-03

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions All in One SEO versions prior to 5.0.2.1
Description Unauthenticated users can execute arbitrary shortcodes registered on the site because the plugin fails to correctly determine which shortcodes are present in content derived from user input before stripping them. On sites upgraded from older versions, the protection is disabled entirely, allowing the issue to be triggered without crafted input. This affects over 3 million WordPress sites.
Recommendations Update to version 5.0.2.1 or later. Audit all registered shortcodes to understand the potential risk surface. Check untrusted-input fields, such as comments and submissions, for shortcode-syntax patterns.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-19856

Affected Products

All In One Seo