WordPress Plugin Vulnerabilities
All in One SEO < 5.0.2.1 - Unauthenticated Arbitrary Shortcode Execution via Search Query
Description
The plugin does not correctly determine which shortcodes are present in content derived from user input before deciding which ones to strip, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. On sites upgraded from older versions the protection is disabled outright, making the issue reachable without any crafted input.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
INJECTION
OWASP top 10
CVSS
Miscellaneous
Original Researcher
Jakub Herman
Submitter
Jakub Herman
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-10-02 (about 20 hours ago)
Added
2026-10-02 (about 2 hours ago)
Last Updated
2026-10-02 (about 2 hours ago)