CVE-2026-19856
Received Received - Intake

All in One SEO WordPress Plugin Shortcode Execution Vulnerability

Vulnerability report for CVE-2026-19856, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: WPScan

Description

The All in One SEO WordPress plugin before 5.0.2.1 does not correctly determine which shortcodes are present in content derived from user input before deciding which ones to strip, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. On sites upgraded from older versions the protection is disabled outright, making the issue reachable without any crafted input.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
all_in_one_seo plugin to 5.0.2.1 (exc)
all_in_one_seo all_in_one_seo to 5.0.2.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the All in One SEO WordPress plugin before version 5.0.2.1. It allows unauthenticated users to execute arbitrary shortcodes by exploiting improper handling of user input in search queries. The plugin fails to correctly identify and strip shortcodes from user-provided content before processing it.

Detection Guidance

Check the installed version of the All in One SEO plugin in WordPress. If it is below 5.0.2.1, the system is vulnerable. Use commands like 'wp plugin list' in WP-CLI or inspect the plugin files for version information in the WordPress admin panel.

Impact Analysis

An attacker could exploit this to execute malicious shortcodes on your WordPress site, potentially leading to unauthorized actions, data leaks, or further compromise of your site. Sites upgraded from older versions are at higher risk as the protection is disabled by default.

Compliance Impact

This vulnerability could lead to unauthorized code execution, potentially violating data protection requirements under GDPR or HIPAA if sensitive data is exposed or modified. Compliance may be impacted if the vulnerability results in data breaches or unauthorized access.

Mitigation Strategies

Update the All in One SEO plugin to version 5.0.2.1 or later immediately. If upgrading is not possible, disable the plugin temporarily until the update is applied. Review and remove any suspicious shortcodes in content that may have been injected.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19856. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart