CVE-2026-82884: All in One SEO < 5.0.0.1 - Contributor+ Stored XSS via ai-assistant Block
The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise and escape some content stored in posts before rendering it back in the post editor, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks that trigger when a higher privileged user edits the post.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue, and who is most likely to trigger the payload?
A user with the WordPress contributor role or higher can store malicious content in a post. The payload triggers when a higher-privileged user later opens that post in the editor.
Which installations are affected?
Installations using All in One SEO versions earlier than 5.0.0.1 are affected. The issue concerns content handled by the plugin's ai-assistant block.
What is the practical impact of successful exploitation?
The vulnerability enables stored cross-site scripting in the context of the higher-privileged user who edits the affected post. The reported impact includes potential compromise of confidentiality, integrity, and availability.