CVE WATCH / VULNERABILITY DETAIL
CVE-2026-19856
MEDIUMCVSS 6.5NVD feed
Published 2 October 2026 · tracked since 3 October 2026
Description
The All in One SEO WordPress plugin before 5.0.2.1 does not correctly determine which shortcodes are present in content derived from user input before deciding which ones to strip, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. On sites upgraded from older ver
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-94505 HIGH 8.1
- CVE-2026-96267 HIGH 7.5
- CVE-2026-75028 HIGH 7.5
- CVE-2026-87115 CRITICAL 9.1
- CVE-2026-93889 HIGH 7.2
- CVE-2026-18443 HIGH 8.8
- CVE-2026-100157 MEDIUM 6.5
- CVE-2026-97341 HIGH 7.2
- CVE-2026-96650 HIGH 7.2
- CVE-2026-97337 HIGH 7.5