Vulnerability  ·  2026-10-05

All in One SEO: arbitrary shortcode execution in breadcrumbs enables content/session tampering

VulnerabilityMedium impactGlobalCVE-2026-100152
NVD published CVE-2026-100152 (CVSS 6.5) on 2026-10-03 for arbitrary shortcode execution in the All in One SEO AI plugin up to 5.0.2 in the breadcrumbs component.
Shortcode execution on an AI SEO plugin can be used to invoke unauthenticated handlers and tamper with page content or leak data on sites using the plugin's AI-driven SEO features. Niche, keep-as-precision CVE.
The breadcrumb rendering path allows execution of arbitrary shortcodes from user-influenced input, so an attacker can run unauthenticated shortcode handlers, potentially echoing sensitive data or performing unexpected actions.
All in One SEO - AI SEO Plugin to Boost SEO Rankings & Traffic WordPress plugin <= 5.0.2
Update beyond 5.0.2 when available. Reference: https://plugins.trac.wordpress.org/browser/all-in-one-seo-pack/tags/5.0.2/app/Common/Breadcrumbs/Breadcrumbs.php#L242
NVD CVE-2026-100152
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →