天下漏洞,尽知其名
MEDIUM

CVE-2026-100152 All in One SEO 任意短代码执行漏洞

影响未授权攻击者可执行任意短代码,可能读取敏感数据或触发其他插件功能

AI 研判

WordPress 插件 All in One SEO(AIOSEO)在 5.0.2 及之前版本中存在任意短代码执行漏洞。由于程序在调用 do_shortcode 前未正确校验传入值,未认证攻击者可借此执行任意短代码。该漏洞编号为 CVE-2026-100152,评级为 MEDIUM(CVSS 6.5)。

影响范围

All in One SEO

All in One SEO 插件所有版本至 5.0.2(含 5.0.2)。

漏洞详情

漏洞类型为任意短代码执行。成因是插件允许用户触发某个动作,但在执行 do_shortcode 之前未对相关值进行充分校验,导致攻击者可注入并执行任意已注册的短代码。利用需要 AIOSEO 面包屑通过区块、小工具、短代码或模板标签渲染在搜索结果页面上。

利用条件与风险

利用前提是站点在搜索结果页面渲染了 AIOSEO 面包屑,且攻击者无需认证即可触发。实战中可能导致敏感信息泄露或借助其他插件短代码造成进一步危害,具体影响取决于站点已注册的短代码。

修复建议

官方已在 5.0.2 之后的版本中修复,建议升级至最新版本。临时缓解措施包括:避免在搜索结果页面渲染 AIOSEO 面包屑,或禁用相关区块、小工具、短代码及模板标签。若无法确认修复版本,请以官方公告为准。

原始情报

The The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.2 This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. This requires the AIOSEO breadcrumb to be rendered on the search results page via the block, widget, shortcode, or template tag.