CVE-2026-85492
Received Received - Intake

DOM-Based XSS in All in One SEO WordPress Plugin

Vulnerability report for CVE-2026-85492, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Wordfence

Description

The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via URL Pathname in all versions up to, and including, 5.0.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user visits a crafted URL. Exploitation requires the victim to hold the aioseo_manage_seo capability and to open the SEO Preview panel in the WordPress admin toolbar while visiting a page with a malicious payload embedded in the URL pathname.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
aioseo all_in_one_seo_plugin to 5.0.1.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a DOM-Based Cross-Site Scripting (XSS) vulnerability in the All in One SEO WordPress plugin. It allows unauthenticated attackers to inject malicious scripts via the URL pathname due to insufficient input sanitization and output escaping. The scripts execute when a user with the aioseo_manage_seo capability opens the SEO Preview panel in the WordPress admin toolbar while visiting a crafted URL.

Detection Guidance

This vulnerability can be detected by checking if the All in One SEO plugin is installed and its version is up to 5.0.1.1. Inspect WordPress admin pages for unexpected scripts in URL paths. Review server logs for unusual requests targeting the SEO Preview panel.

Impact Analysis

An attacker could steal sensitive user data, such as cookies or session tokens, by tricking users into visiting a malicious URL. This could lead to account takeovers, unauthorized actions on behalf of the user, or defacement of the website. Users with the aioseo_manage_seo capability are specifically targeted.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR and HIPAA requirements for protecting user data. Organizations may face fines, legal liabilities, and reputational damage if exploited. Compliance with data protection regulations could be compromised due to unauthorized access to sensitive information.

Mitigation Strategies

Immediately update the All in One SEO plugin to the latest version beyond 5.0.1.1. Remove unnecessary admin capabilities for users. Monitor for suspicious activity in WordPress admin logs and user sessions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85492. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart