What happened
NVD published CVE-2026-100152 (CVSS 6.5) on 2026-10-03 for arbitrary shortcode execution in the All in One SEO AI plugin up to 5.0.2 in the breadcrumbs component.
Why it matters
Shortcode execution on an AI SEO plugin can be used to invoke unauthenticated handlers and tamper with page content or leak data on sites using the plugin's AI-driven SEO features. Niche, keep-as-precision CVE.
Attack vector
The breadcrumb rendering path allows execution of arbitrary shortcodes from user-influenced input, so an attacker can run unauthenticated shortcode handlers, potentially echoing sensitive data or performing unexpected actions.
Affected systems
All in One SEO - AI SEO Plugin to Boost SEO Rankings & Traffic WordPress plugin <= 5.0.2
Mitigation
Update beyond 5.0.2 when available. Reference: https://plugins.trac.wordpress.org/browser/all-in-one-seo-pack/tags/5.0.2/app/Common/Breadcrumbs/Breadcrumbs.php#L242