CVE-2026-85492 All in One SEO 基于DOM的跨站脚本漏洞
影响攻击者可注入恶意脚本,在管理员浏览器中执行
WordPress 插件 All in One SEO 存在基于 DOM 的跨站脚本漏洞,影响 5.0.1.1 及之前所有版本。由于对 URL 路径名输入过滤和输出转义不足,未认证攻击者可构造恶意 URL 注入任意 Web 脚本。
影响范围
All in One SEO 插件所有版本至 5.0.1.1(含)。
漏洞详情
漏洞类型为基于 DOM 的跨站脚本(XSS),成因是插件对 URL 路径名(pathname)未做充分的输入净化和输出转义。攻击者可将恶意脚本嵌入 URL 路径,当受害者访问该链接并打开 WordPress 管理工具栏中的 SEO 预览面板时脚本被执行。
利用条件与风险
利用需受害者具备 aioseo_manage_seo 权限并主动打开 SEO 预览面板,属于需要一定交互的场景,但可针对管理员实施定向攻击,实战风险中等。
修复建议
建议升级 All in One SEO 插件至 5.0.1.1 之后的修复版本;暂无公开信息说明具体修复版本号,临时缓解措施为限制具备 aioseo_manage_seo 权限的账号并谨慎点击可疑链接。
The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via URL Pathname in all versions up to, and including, 5.0.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user visits a crafted URL. Exploitation requires the victim to hold the aioseo_manage_seo capability and to open the SEO Preview panel in the WordPress admin toolbar while visiting a page with a malicious payload embedded in the URL pathname.