Impact
The All in One SEO plugin allows unauthenticated users to inject arbitrary shortcodes through the 's' search query parameter because the value is not validated before being passed to do_shortcode. This flaw can result in execution of any PHP code embedded in a shortcode, granting an attacker full control over the web application and potentially the underlying server. The vulnerability is a classic example of CWE‑94, where untrusted input is executed as code.
Affected Systems
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) for WordPress, versions up to and including 5.0.2.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. No EPSS data is available, and the issue is not listed in the CISA KEV catalog, suggesting limited reported exploitation. However, because the flaw enables arbitrary code execution on public web pages, the risk remains high if the breadcrumb feature is rendered on search result pages via a block, widget, shortcode, or template tag. The likely attack path involves crafting a URL with an 's' parameter containing a malicious shortcode, accessing the page to trigger the rendering, and thereby executing code on the target site.
OpenCVE Enrichment