WordPress Plugin Vulnerabilities

All in One SEO < 5.0.2.1 - Unauthenticated Arbitrary Shortcode Execution via Search Query

Description

The plugin does not correctly determine which shortcodes are present in content derived from user input before deciding which ones to strip, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. On sites upgraded from older versions the protection is disabled outright, making the issue reachable without any crafted input.

Proof of Concept

Affects Plugins

Fixed in 5.0.2.1

References

Classification

Type
INJECTION
OWASP top 10

Miscellaneous

Original Researcher
Jakub Herman
Submitter
Jakub Herman
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-10-02 (about 20 hours ago)
Added
2026-10-02 (about 2 hours ago)
Last Updated
2026-10-02 (about 2 hours ago)

Other