Threats Tagged 'cve-2026-100152'
View all threats tagged with 'cve-2026-100152'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-100152'
Click on any threat for detailed analysis and mitigation recommendations
The All in One SEO – AI SEO Plugin for WordPress up to version 5.0.2 contains a vulnerability that allows unauthenticated attackers to execute arbitrary shortcodes. This occurs because the plugin does not properly validate input before calling do_shortcode, specifically when the AIOSEO breadcrumb is rendered on search results pages via blocks, widgets, shortcodes, or template tags. The vulnerability has a medium severity rating with a CVSS score of 6.5. Join the discussion | GCVE Database | 10/03/2026, 06:31:12 UTC Added: 10/03/2026, 17:21:29 UTC |
The The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.2 This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. This requires the AIOSEO breadcrumb to be rendered on the search results page via the block, widget, shortcode, or template tag. Join the discussion | CVE Database V5 | 10/03/2026, 05:29:16 UTC Added: 10/03/2026, 05:46:37 UTC |
Showing 1 to 2 of 2 results