PT-2026-42103 · WordPress · All In One Seo

Riadh Bouchahoua

·

Published

2026-05-20

·

Updated

2026-05-20

·

CVE-2026-5075

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions All in One SEO versions prior to 4.9.8
Description The All in One SEO plugin for WordPress allows sensitive internal option data to be passed to the wp localize script() function in post editor contexts without effective masking for low-privilege users. This leads to sensitive information exposure via the 'internalOptions' localized script data. Authenticated attackers with contributor-level access or higher can view configured API/OAuth tokens and license-related values by inspecting the page source.
Recommendations Update to a version newer than 4.9.7.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-5075

Affected Products

All In One Seo