Description
WordPress Plugin All in One SEO-Best WordPress SEO-Easily Improve SEO Rankings & Increase Traffic is prone to multiple vulnerabilities, including SQL injection and privilege escalation vulnerabilities. Exploiting these issues may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database, or to perform otherwise restricted actions and subsequently access protected REST API endpoints. WordPress Plugin All in One SEO-Best WordPress SEO-Easily Improve SEO Rankings & Increase Traffic versions between 4.0.0 - 4.1.5.2 and 4.1.3.1 - 4.1.5.2 (inclusively) are vulnerable.
Remediation
Update to plugin version 4.1.5.3 or latest
References
Related Vulnerabilities
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2016-3690)
Oracle JRE CVE-2013-5812 Vulnerability (CVE-2013-5812)
WordPress Plugin Strong Testimonials Multiple Cross-Site Scripting Vulnerabilities (2.31.4)
WordPress Plugin Kadence WooCommerce Email Designer PHP Object Injection (1.5.6)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2020-9546)