PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-85492 smub CVE debrief

The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via URL Pathname in all versions up to, and including, 5.0.1.1 due to insufficient input sanitization and output escaping. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user visits a crafted URL. The plugin's lack of proper input validation and output escaping enables the exploitation, which requires the victim to hold the aioseo_manage_seo capability and to open the SEO Preview panel in the WordPress admin toolbar while visiting

Vendor
smub
Product
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-02
Original CVE updated
2026-10-03
Advisory published
2026-10-02
Advisory updated
2026-10-03

Who should care

WordPress administrators and security teams should assess exposure of the SEO Preview panel to potential DOM-Based Cross-Site Scripting attacks. They must verify the presence of this vulnerability in their WordPress installations and prioritize remediation due to the CVSS score of 6.1 and MEDIUM severity. Defenders should also review compensating controls for exposed systems while remediation is scheduled and verified, and monitor for suspicious activity

Why it matters

CVE-2026-85492 is a DOM-Based Cross-Site Scripting vulnerability in the All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress. Defenders should prioritize verifying the presence of this vulnerability in their WordPress installations and assess exposure of the SEO Preview panel.

  • Defenders must verify the presence of this vulnerability in their WordPress installations.
  • Exposure of the SEO Preview panel to potential DOM-Based Cross-Site Scripting attacks requires assessment.
  • Successful exploitation could lead to injection of arbitrary web scripts.
  • Remediation priority is medium due to the CVSS score of 6.1 and MEDIUM severity.

Technical summary

The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via URL Pathname in all versions up to, and including, 5.0.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user visits a crafted URL. The vulnerability requires the victim to hold the aioseo_manage_seo capability and to open the SEO Preview panel in the WordPress admin toolbar while visiting a page with a malicious payload embedded in the URL pathname.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their WordPress installations and assess exposure of the SEO Preview panel.

Recommended defensive actions

  • Verify the presence of the All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin in your WordPress installation
  • Assess exposure of the SEO Preview panel to potential DOM-Based Cross-Site Scripting attacks
  • Restrict access to the SEO Preview panel to authorized users only
  • Monitor for suspicious activity related to the plugin
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 6.1 and MEDIUM severity. The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via URL Pathname in all versions up to, and including, 5.0.1.1 due to insufficient input sanitization and output escaping. The source details indicate that exploitation requires the victim to hold the aioseo_manage_seo capability and to

Sources and references

Verified primary and authoritative sources

  • CVE-2026-85492 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-85492

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-85492 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85492

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/all-in-one-seo-pack/tags/5.0.1.1/dist/Lite/assets/js/GoogleSearchPreview.8286359f.js

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/all-in-one-seo-pack/tags/5.0.1.1/dist/Lite/assets/js/app-core.36551fe5.js

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.