CVE-2026-19856Medium· 6.5▾ SunlitThe All in One SEO WordPress plugin before 5.0.2.1 does not correctly determine which shortcodes are present in content derived from user input before deciding which ones to strip, allowing unauthenticated users to execute arbitrary shor…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The All in One SEO WordPress plugin before 5.0.2.1 does not correctly determine which shortcodes are present in content derived from user input before deciding which ones to strip, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. On sites upgraded from older versions the protection is disabled outright, making the issue reachable without any crafted input.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-14884High· 7.2A vulnerability was detected in D-Link DIR-605 202WWB03
CVE-2026-103114Medium· 6.3A vulnerability was identified in OS4ED openSIS-Classic up to 9.3
CVE-2026-103113Medium· 4.7A vulnerability was determined in OS4ED openSIS-Classic up to 9.3
CVE-2026-102913High· 7.3A security flaw has been discovered in SourceCodester Car Driving School Management System 1.0
CVE-2026-102912Medium· 4.7A vulnerability was identified in SourceCodester Online Leave Management System 1.0
CVE-2026-102910High· 7.3A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0