PT-2022-26457 · WordPress · All In One Seo Pro

Rafie Muhammad

·

Published

2022-11-08

·

Updated

2022-11-09

·

CVE-2022-42494

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions All in One SEO Pro plugin versions <= 4.2.5.1
Description The issue is related to a Server Side Request Forgery (SSRF) vulnerability. This type of vulnerability allows an attacker to trick the server into making requests to unintended locations, potentially leading to unauthorized access or data exposure.
Recommendations For All in One SEO Pro plugin versions <= 4.2.5.1, update to a version higher than 4.2.5.1 to resolve the issue. As a temporary workaround, consider restricting access to the plugin's functionality to minimize the risk of exploitation.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-42494

Affected Products

All In One Seo Pro