Impact
The All in One SEO WordPress plugin before version 5.0.0.1 fails to sanitize and escape certain content stored within posts when rendering it back into the post editor. This flaw allows users with the contributor role or higher to inject JavaScript payloads that are stored in posts. When a higher‑privileged user subsequently opens the same post in the editor, the unsanitized payload is rendered, resulting in Stored Cross‑Site Scripting. The weakness is classified as CWE‑79, enabling attackers to hijack the victim’s browser session, steal credentials, or redirect users to malicious sites.
Affected Systems
All installations of the All in One SEO WordPress plugin running a version earlier than 5.0.0.1 are vulnerable. The issue applies to any WordPress site that uses the plugin regardless of the core WordPress version, with the limitation that exploitation requires a user who can edit posts with a contributor level or higher.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity. No EPSS score is available, so the probability of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a contributor or higher to inject malicious content into a post, and a later edit by a higher‑privileged user to trigger the script. When these conditions are satisfied, the payload runs in the context of the editing user’s browser, potentially compromising credentials or enabling session hijacking. Administrators should treat the risk as significant if contributor access is not tightly controlled.
OpenCVE Enrichment