DOM-Based Cross-Site Scripting Vulnerability in All in One SEO Plugin for WordPress
CVE-2026-85492
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-85492?
The All in One SEO β AI SEO Plugin for WordPress is susceptible to DOM-Based Cross-Site Scripting due to insufficient input sanitization and output escaping in versions up to 5.0.1.1. This vulnerability allows unauthenticated attackers to inject malicious web scripts via URL pathnames. When a user with the aioseo_manage_seo capability accesses the SEO Preview panel while visiting a page with a crafted URL, arbitrary scripts can execute, potentially compromising the site's security.
Affected Version(s)
All in One SEO β AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) 0 <= 5.0.1.1