CVE-2026-82884 PUBLISHED

All in One SEO < 5.0.0.1 - Contributor+ Stored XSS via ai-assistant Block

Assigner: WPScan
Reserved: 31.08.2026 Published: 02.09.2026 Updated: 02.09.2026

The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise and escape some content stored in posts before rendering it back in the post editor, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks that trigger when a higher privileged user edits the post.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 6.8

Product Status

Vendor Unknown
Product All in One SEO
Versions Default: unaffected
  • affected from 0 to 5.0.0.1 (excl.)

Credits

  • Asaf Mozes finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE