Description
The All in One SEO WordPress plugin before 5.0.2.1 does not correctly determine which shortcodes are present in content derived from user input before deciding which ones to strip, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. On sites upgraded from older versions the protection is disabled outright, making the issue reachable without any crafted input.
Published: 2026-10-02
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Arbitrary Shortcode Execution
Action: Patch
AI Analysis

Impact

The vulnerability allows unauthenticated users to execute any shortcode registered on the site because the plugin fails to correctly determine which shortcodes appear in content derived from user input before stripping them. Because the search query can be crafted, an attacker can insert a shortcode that triggers arbitrary code execution. Sites upgraded from older versions have the protection disabled entirely, enabling the issue to be reached without custom payload. This flaw can lead to full code execution on the web server, with potential for data exfiltration, defacement, or further compromise.

Affected Systems

Affected are installations of the WordPress All in One SEO plugin with versions earlier than 5.0.2.1. This includes the open‑source plugin distributed at All in One SEO. No other vendors are listed. If a site uses a custom fork or a different plugin name, the specific affected version should be checked against the version threshold.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity. No EPSS score is available, but the attack vector is clearly unauthenticated remote via the search functionality, known to be exposed to all visitors. Since the flaw is not listed in the CISA KEV catalog, it does not appear to have been actively exploited at the time of publication. However, the ability to execute arbitrary code without authentication makes it a high‑risk vector if a plugin version is not patched. An attacker could send a crafted search request to invoke a malicious shortcode, potentially gaining full server access.

Generated by OpenCVE AI on October 2, 2026 at 19:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the All in One SEO plugin to version 5.0.2.1 or later, which removes the flawed input handling and disables arbitrary shortcode execution.
  • If the update cannot be performed immediately, disable or remove the search feature that triggers shortcode rendering, or restrict the search endpoint to authenticated users only.
  • Scan the website for registered shortcodes and remove any that are unnecessary or potentially dangerous, and review plugin settings to ensure that only trusted shortcodes are enabled.
  • Keep the core WordPress installation and other plugins up to date, as these updates often contain additional security hardening that can reduce the impact of similar flaws.

Generated by OpenCVE AI on October 2, 2026 at 19:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Fri, 02 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
Description The All in One SEO WordPress plugin before 5.0.2.1 does not correctly determine which shortcodes are present in content derived from user input before deciding which ones to strip, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. On sites upgraded from older versions the protection is disabled outright, making the issue reachable without any crafted input.
Title All in One SEO < 5.0.2.1 - Unauthenticated Arbitrary Shortcode Execution via Search Query
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-02T18:25:43.042Z

Reserved: 2026-08-14T09:46:29.642Z

Link: CVE-2026-19856

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T19:16:41.247

Modified: 2026-10-02T19:16:41.247

Link: CVE-2026-19856

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T19:30:17Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')