Stored Cross-Site Scripting Vulnerability in All in One SEO Plugin
CVE-2026-82884
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 2 September 2026
Badges
What is CVE-2026-82884?
The All in One SEO plugin for WordPress, prior to version 5.0.0.1, contains a vulnerability where it fails to properly sanitize and escape content stored within posts. This oversight allows users with contributor roles and above to conduct Stored Cross-Site Scripting attacks. The vulnerability is triggered when a privileged user edits a post that contains the malicious content, potentially leading to unauthorized script execution and compromising site integrity.
Affected Version(s)
All in One SEO 0 < 5.0.0.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved