CVE-2026-19856 | All in One SEO Plugin up to 5.0.2.0 on WordPress Shortcode injection

SecurityVulns

A vulnerability was found in All in One SEO Plugin up to 5.0.2.0 on WordPress and classified as critical. The impacted element is an unknown function of the component Shortcode Handler. Executing a manipulation can lead to injection.

This vulnerability is registered as CVE-2026-19856. It is possible to launch the attack remotely. No exploit is available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More