Sceawere

Vulnerability Detail

CVE-2026-85492UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DOM-Based XSS in AIOSEO

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
13h ago
Vendor
smub
Product
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via URL Pathname in all versions up to, and including, 5.0.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user visits a crafted URL. Exploitation requires the victim to hold the aioseo_manage_seo capability and to open the SEO Preview panel in the WordPress admin toolbar while visiting a page with a malicious payload embedded in the URL pathname.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-10-02T10:17:08.707Z",
  "pubdate": "2026-10-02T10:17:08.707Z",
  "executiveSummary": "The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) is susceptible to a DOM-based Cross-Site Scripting (XSS) vulnerability. This flaw stems from improper sanitization and escaping of URL pathnames processed by the plugin's frontend functionality. The vulnerability permits unauthenticated attackers to embed malicious JavaScript payloads within URL paths. When a victim with the aioseo_manage_seo capability visits a crafted URL and interacts with the SEO Preview panel within the WordPress admin toolbar, the payload executes within the context of their authenticated session. This creates a significant security risk, as successful exploitation allows for unauthorized script execution, potentially leading to administrative account compromise, session hijacking, or unauthorized configuration changes within the WordPress environment. The vulnerability affects all versions up to and including 5.0.1.1.",
  "technicalDetails": "The vulnerability resides in the way the plugin processes URL pathnames to populate data within the SEO Preview panel located in the WordPress admin toolbar. Because the plugin fails to sufficiently sanitize user-supplied input from the URL pathname or implement appropriate output escaping when rendering this data into the DOM, the application becomes vulnerable to DOM-based XSS.\nThe exploitation flow begins when an attacker crafts a malicious URL containing a JavaScript payload appended to the pathname. This URL does not require the attacker to have any specific WordPress privileges. The attacker then lures a target, who must possess the 'aioseo_manage_seo' capability (typically an Administrator, Editor, or designated SEO Manager), into visiting the crafted URL while they are logged into the WordPress administrative backend.\nOnce the victim visits the link, the plugin's client-side code retrieves the malicious pathname string and dynamically injects it into the DOM to render the SEO preview interface. Due to the lack of context-aware escaping, the browser interprets the injected payload as executable script rather than plain text. This execution occurs exclusively when the victim opens the SEO Preview panel in the WordPress admin toolbar, triggering the secondary step of the attack.\nUpon successful execution, the injected script runs within the victim's browser session. Given that the victim is an authenticated user with elevated capabilities, the script can perform any action the user is authorized to execute. This includes making unauthorized requests to the WordPress REST API or admin-ajax.php, such as modifying SEO settings, injecting malicious redirects, altering site metadata, or creating new administrative accounts. The scope of impact is limited to the context of the user session, but because this involves high-privileged users, the potential for site-wide compromise is critical. The vulnerability is restricted to environments where the victim has active administrative access and interacts with the specific vulnerable component provided by the plugin."
}
CVE-2026-85492: DOM-Based XSS in AIOSEO (MEDIUM Severity, CVSS: 6.1) | Sceawere