PatchSiren cyber security CVE debrief
CVE-2026-85492 smub CVE debrief
The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via URL Pathname in all versions up to, and including, 5.0.1.1 due to insufficient input sanitization and output escaping. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user visits a crafted URL. The plugin's lack of proper input validation and output escaping enables the exploitation, which requires the victim to hold the aioseo_manage_seo capability and to open the SEO Preview panel in the WordPress admin toolbar while visiting
- Vendor
- smub
- Product
- All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-02
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-02
- Advisory updated
- 2026-10-03
Who should care
WordPress administrators and security teams should assess exposure of the SEO Preview panel to potential DOM-Based Cross-Site Scripting attacks. They must verify the presence of this vulnerability in their WordPress installations and prioritize remediation due to the CVSS score of 6.1 and MEDIUM severity. Defenders should also review compensating controls for exposed systems while remediation is scheduled and verified, and monitor for suspicious activity
Why it matters
CVE-2026-85492 is a DOM-Based Cross-Site Scripting vulnerability in the All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress. Defenders should prioritize verifying the presence of this vulnerability in their WordPress installations and assess exposure of the SEO Preview panel.
- Defenders must verify the presence of this vulnerability in their WordPress installations.
- Exposure of the SEO Preview panel to potential DOM-Based Cross-Site Scripting attacks requires assessment.
- Successful exploitation could lead to injection of arbitrary web scripts.
- Remediation priority is medium due to the CVSS score of 6.1 and MEDIUM severity.
Technical summary
The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via URL Pathname in all versions up to, and including, 5.0.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user visits a crafted URL. The vulnerability requires the victim to hold the aioseo_manage_seo capability and to open the SEO Preview panel in the WordPress admin toolbar while visiting a page with a malicious payload embedded in the URL pathname.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their WordPress installations and assess exposure of the SEO Preview panel.
Recommended defensive actions
- Verify the presence of the All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin in your WordPress installation
- Assess exposure of the SEO Preview panel to potential DOM-Based Cross-Site Scripting attacks
- Restrict access to the SEO Preview panel to authorized users only
- Monitor for suspicious activity related to the plugin
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 6.1 and MEDIUM severity. The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via URL Pathname in all versions up to, and including, 5.0.1.1 due to insufficient input sanitization and output escaping. The source details indicate that exploitation requires the victim to hold the aioseo_manage_seo capability and to
Sources and references
Verified primary and authoritative sources
-
CVE-2026-85492 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-85492
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-85492 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85492
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/all-in-one-seo-pack/tags/5.0.1.1/dist/Lite/assets/js/GoogleSearchPreview.8286359f.js
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/all-in-one-seo-pack/tags/5.0.1.1/dist/Lite/assets/js/app-core.36551fe5.js
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.