Impact
The All in One SEO – AI SEO Plugin for WordPress is afflicted by a DOM‑Based Cross‑Site Scripting flaw that originates from the URL pathname. A crafted URL can inject arbitrary JavaScript into the page that is rendered when a user opens the SEO Preview panel with the aioseo_manage_seo capability. Because the plugin does not adequately sanitize or escape this component, attackers can execute scripts in the context of the victim’s browser, potentially leading to session hijacking, credential theft, or defacement.
Affected Systems
Vulnerable systems are WordPress sites that use the smub All in One SEO – AI SEO Plugin version 5.0.1.1 or any earlier release. The issue applies to all installations of the plugin, regardless of other configuration, until the update to 5.0.2 is applied.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity, and the lack of an EPSS value signals that the current exploitation probability is not quantified. The attack requires that the victim possess the aioseo_manage_seo capability and visits a URL containing the malicious payload while the SEO Preview panel is opened, making it a local‑oriented attack that depends on user interaction. Because the vulnerability is not listed in CISA’s KEV catalog, there is no evidence of active exploitation in the wild at this time, though the nature of XSS makes it a valuable target for attackers seeking to compromise administrative sessions.
OpenCVE Enrichment