CVE-2026-19856

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The All in One SEO WordPress plugin before 5.0.2.1 does not correctly determine which shortcodes are present in content derived from user input before deciding which ones to strip, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. On sites upgraded from older versions the protection is disabled outright, making the issue reachable without any crafted input.

0.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-03: 210-03
Full discourse2 posts
  • DEGEN 👑@iamjustape

    Fixing CVE-2026-19856 (All in One SEO): 1. Update to 5.0.2.1+ this is the complete fix, no extra config needed 2. Upgraded from an older version? VERIFY stripping actually works post-update don't trust the version number alone 3. Audit what your OTHER registered shortcodes actually do that's the real risk surface here 4. Check untrusted-input fields (comments, submissions) for shortcode-syntax patterns

    1000038
    4.0K followersView on X
  • DEGEN 👑@iamjustape

    Good Morning everyone. New today: CVE-2026-19856 in All in One SEO (3M+ WordPress sites). Official CVSS score: medium. Don't let that fool you. Unauthenticated users can trigger ANY shortcode registered on your site. On sites upgraded from older versions, the protection is reportedly disabled outright no crafted input needed.

    0000043
    4.0K followersView on X

Explore more