WP Vulnerability WatchVulnerability data as of October 3, 2026

Vulnerability alerts / October 2, 2026

Vulnerability in All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) — CVE-2026-85492

MediumSeverity
CVSS 6.1
0.4%Estimated exploit probability
EPSS
3,000,000+ sitesInstalls
5.0.2Fixed in

What to do now

Update All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) to 5.0.2 or later.

Affected versions

  • Everything up to and including 5.0.1.1

Affected: All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) (plugin, all-in-one-seo-pack)

Check: The plugin on wordpress.org / Our record for All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

What the vulnerability is

The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via URL Pathname in all versions up to, and including, 5.0.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user visits a crafted URL. Exploitation requires the victim to hold the aioseo_manage_seo capability and to open the SEO Preview panel in the WordPress admin toolbar while visiting a page with a malicious payload embedded in the URL pathname.

This description is reproduced verbatim from the public vulnerability record.

Sources

See other alerts