Description
The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via URL Pathname in all versions up to, and including, 5.0.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user visits a crafted URL. Exploitation requires the victim to hold the aioseo_manage_seo capability and to open the SEO Preview panel in the WordPress admin toolbar while visiting a page with a malicious payload embedded in the URL pathname.
Published: 2026-10-02
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (XSS)
Action: Update Plugin
AI Analysis

Impact

The All in One SEO – AI SEO Plugin for WordPress is afflicted by a DOM‑Based Cross‑Site Scripting flaw that originates from the URL pathname. A crafted URL can inject arbitrary JavaScript into the page that is rendered when a user opens the SEO Preview panel with the aioseo_manage_seo capability. Because the plugin does not adequately sanitize or escape this component, attackers can execute scripts in the context of the victim’s browser, potentially leading to session hijacking, credential theft, or defacement.

Affected Systems

Vulnerable systems are WordPress sites that use the smub All in One SEO – AI SEO Plugin version 5.0.1.1 or any earlier release. The issue applies to all installations of the plugin, regardless of other configuration, until the update to 5.0.2 is applied.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate severity, and the lack of an EPSS value signals that the current exploitation probability is not quantified. The attack requires that the victim possess the aioseo_manage_seo capability and visits a URL containing the malicious payload while the SEO Preview panel is opened, making it a local‑oriented attack that depends on user interaction. Because the vulnerability is not listed in CISA’s KEV catalog, there is no evidence of active exploitation in the wild at this time, though the nature of XSS makes it a valuable target for attackers seeking to compromise administrative sessions.

Generated by OpenCVE AI on October 2, 2026 at 10:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the All in One SEO – AI SEO Plugin to version 5.0.2 or later.
  • If the plugin is not essential, uninstall or disable it completely.
  • Restrict the aioseo_manage_seo capability to trusted administrators only and limit the usage of the SEO Preview panel for regular users.

Generated by OpenCVE AI on October 2, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Description The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via URL Pathname in all versions up to, and including, 5.0.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user visits a crafted URL. Exploitation requires the victim to hold the aioseo_manage_seo capability and to open the SEO Preview panel in the WordPress admin toolbar while visiting a page with a malicious payload embedded in the URL pathname.
Title All in One SEO <= 5.0.1.1 - Reflected DOM-Based Cross-Site Scripting via URL Pathname
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-02T09:25:56.509Z

Reserved: 2026-09-03T21:44:22.180Z

Link: CVE-2026-85492

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T10:17:08.707

Modified: 2026-10-02T13:18:55.613

Link: CVE-2026-85492

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T10:30:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')