Arbitrary Shortcode Execution in All in One SEO Plugin for WordPress
CVE-2026-100152
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-100152?
The All in One SEO Plugin for WordPress is susceptible to arbitrary shortcode execution due to improper validation of user input. This vulnerability affects all versions up to 5.0.2, allowing unauthenticated attackers to execute arbitrary shortcodes if the AIOSEO breadcrumb is rendered on the search results page using various methods such as blocks, widgets, shortcodes, or template tags. This flaw poses a serious risk to websites utilizing the plugin, emphasizing the need for immediate updates and enhanced security measures.
Affected Version(s)
All in One SEO β AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) 0 <= 5.0.2