Description
The The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.2 This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. This requires the AIOSEO breadcrumb to be rendered on the search results page via the block, widget, shortcode, or template tag.
Published: 2026-10-03
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution via shortcode injection
Action: Immediate Patch
AI Analysis

Impact

The All in One SEO plugin allows unauthenticated users to inject arbitrary shortcodes through the 's' search query parameter because the value is not validated before being passed to do_shortcode. This flaw can result in execution of any PHP code embedded in a shortcode, granting an attacker full control over the web application and potentially the underlying server. The vulnerability is a classic example of CWE‑94, where untrusted input is executed as code.

Affected Systems

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) for WordPress, versions up to and including 5.0.2.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. No EPSS data is available, and the issue is not listed in the CISA KEV catalog, suggesting limited reported exploitation. However, because the flaw enables arbitrary code execution on public web pages, the risk remains high if the breadcrumb feature is rendered on search result pages via a block, widget, shortcode, or template tag. The likely attack path involves crafting a URL with an 's' parameter containing a malicious shortcode, accessing the page to trigger the rendering, and thereby executing code on the target site.

Generated by OpenCVE AI on October 3, 2026 at 06:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the plugin to a version that removes the vulnerability (5.0.3 or later).
  • Disable breadcrumb rendering on search results pages or remove the block, widget, shortcode, or template tag that triggers the vulnerable execution.
  • If an immediate upgrade is not possible, temporarily disable the plugin or apply a custom filter to block do_shortcode from executing on the 's' parameter, and consider adding a WAF rule to detect and prevent shortcode syntax in inbound search queries.

Generated by OpenCVE AI on October 3, 2026 at 06:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.2 This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. This requires the AIOSEO breadcrumb to be rendered on the search results page via the block, widget, shortcode, or template tag.
Title All in One SEO <= 5.0.2 - Unauthenticated Arbitrary Shortcode Execution via 's' Search Query Parameter
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:44.600Z

Reserved: 2026-09-25T12:04:15.445Z

Link: CVE-2026-100152

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:19.405Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:37.713

Modified: 2026-10-03T16:16:30.773

Link: CVE-2026-100152

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T06:30:18Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')