Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-19856
Unknown All in One SEO — All in One SEO < 5.0.2.1 - Unauthenticated Arbitrary Shortcode Execution via Search Query
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U L L N 6.5 .0018 7.2 —
AFFECTED
Product Versions Fixed
All in One SEO unspecified —
TIMELINE
Aug 14 Reserved by WPScan
Oct 2 Published (CNA: WPScan)
Oct 6 EXPLOIT PUBLISHED — CVE-2026-19856 (Unknown All in One SEO). Public exploit reference added.
Description
The All in One SEO WordPress plugin before 5.0.2.1 does not correctly determine which shortcodes are present in content derived from user input before deciding which ones to strip, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. On sites upgraded from older versions the protection is disabled outright, making the issue reachable without any crafted input.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 14, 2026 | Reserved | Reserved by WPScan |
| October 2, 2026 | Published | Published (CNA: WPScan) |
| October 6, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-19856 (Unknown All in One SEO). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Unknown | All in One SEO | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-19856 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.