All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic Vulnerability (CVE-2026-85492)

On this page

Security Alert Summary

The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress contains a DOM-based cross-site scripting (XSS) vulnerability via the URL pathname in all versions up to and including 5.0.1.1. Insufficient input sanitization and output escaping allow unauthenticated attackers to inject arbitrary scripts that execute when a user visits a crafted URL. Successful exploitation requires the victim to hold the aioseo_manage_seo capability and to open the SEO Preview panel in the WordPress admin toolbar while visiting the malicious URL.

CVE Details

  • CVE ID: CVE-2026-85492
  • Affected component: All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress
  • Affected versions: all versions up to and including 5.0.1.1
  • Published: October 2, 2026 at 10:17:08 AM UTC
  • Last modified: October 2, 2026 at 1:18:55 PM UTC
  • CVSS v3.1: Base Score 6.1, MEDIUM — Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • Authentication / privileges / user interaction (CVSS): Privileges Required: None (no attacker authentication required); User Interaction: Required
  • Primary impact: Confidentiality: Low; Integrity: Low; Availability: None
  • Weakness: CWE-79 (Improper Neutralization of Input During Web Page Generation or Script)

Technical Details

This is a DOM-based XSS vulnerability triggered by a crafted value in the page URL pathname. The plugin does not sufficiently sanitize input taken from the URL pathname or properly escape output in the JavaScript that renders the SEO preview, allowing an attacker to inject arbitrary web scripts into pages that will execute when a targeted admin or editor visits a specially crafted link.

The vulnerability description identifies the SEO Preview panel in the WordPress admin toolbar and the requirement that the victim hold the aioseo_manage_seo capability and open that panel while visiting the page with the malicious pathname. The referenced JavaScript assets include files such as GoogleSearchPreview.8286359f.js and app-core.36551fe5.js, which are implicated by the provided references.

When triggered, injected scripts run in the context of the user who opened the preview panel. Impact is limited by the affected users’ privileges; the CVSS assessment reports low confidentiality and integrity impact and no availability impact, consistent with a targeted script execution that can expose or manipulate limited data visible to that user.


How This Could Impact Your Website

Consider a site with multiple WordPress users: the site owner, internal editors or staff, and external contractors or contributors. An attacker could craft a URL containing a payload and share it with a target who has the aioseo_manage_seo capability. If that user opens the URL and then opens the SEO Preview panel in the admin toolbar, the payload can execute in their browser.

  • Exposure of information available to the targeted user, such as internal profile details or other data visible in the admin interface, is possible given the confidentiality impact reported as low.
  • Attackers could use any exposed contact details to increase the risk of targeted phishing or social engineering against staff or contractors.
  • Because the vulnerability requires the victim to perform an action in the admin interface, the risk is focused and user-interaction dependent rather than an automatic site-wide compromise.

If youre unsure whether your site is affected or how to assess your current user roles and plugins, it may be worth having a professional review your setup.


Recommended Actions

  • Update the affected plugin as soon as a patched version is available.
  • Review and reduce unnecessary user roles and capabilities, particularly users granted aioseo_manage_seo or other high-content roles.
  • Enforce strong passwords and enable two-factor authentication for editors and administrators.
  • Remove unused or unmaintained plugins to reduce attack surface.
  • Monitor site activity and admin sessions for unusual behavior or unexpected admin-panel actions.

If youd like help reviewing your plugins, user roles, or overall WordPress security posture, our team at Freshy is happy to help.


References