Arbitrary Shortcode Execution in All in One SEO Plugin for WordPress
CVE-2026-100152

6.5MEDIUM

What is CVE-2026-100152?

The All in One SEO Plugin for WordPress is susceptible to arbitrary shortcode execution due to improper validation of user input. This vulnerability affects all versions up to 5.0.2, allowing unauthenticated attackers to execute arbitrary shortcodes if the AIOSEO breadcrumb is rendered on the search results page using various methods such as blocks, widgets, shortcodes, or template tags. This flaw poses a serious risk to websites utilizing the plugin, emphasizing the need for immediate updates and enhanced security measures.

Affected Version(s)

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) 0 <= 5.0.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kuba
.