Impact
The vulnerability allows unauthenticated users to execute any shortcode registered on the site because the plugin fails to correctly determine which shortcodes appear in content derived from user input before stripping them. Because the search query can be crafted, an attacker can insert a shortcode that triggers arbitrary code execution. Sites upgraded from older versions have the protection disabled entirely, enabling the issue to be reached without custom payload. This flaw can lead to full code execution on the web server, with potential for data exfiltration, defacement, or further compromise.
Affected Systems
Affected are installations of the WordPress All in One SEO plugin with versions earlier than 5.0.2.1. This includes the open‑source plugin distributed at All in One SEO. No other vendors are listed. If a site uses a custom fork or a different plugin name, the specific affected version should be checked against the version threshold.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. No EPSS score is available, but the attack vector is clearly unauthenticated remote via the search functionality, known to be exposed to all visitors. Since the flaw is not listed in the CISA KEV catalog, it does not appear to have been actively exploited at the time of publication. However, the ability to execute arbitrary code without authentication makes it a high‑risk vector if a plugin version is not patched. An attacker could send a crafted search request to invoke a malicious shortcode, potentially gaining full server access.
OpenCVE Enrichment