PT-2022-9593 · WordPress · All In One Seo

Marc Montpas

·

Published

2022-01-17

·

Updated

2022-10-25

·

CVE-2021-25036

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions All in One SEO WordPress plugin versions prior to 4.1.5.3
Description The issue allows bad actors to access protected REST API endpoints, potentially enabling users with low-privileged accounts to perform remote code execution on affected sites. This could grant unauthorized access to sensitive areas of the site.
Recommendations For versions prior to 4.1.5.3, update to version 4.1.5.3 or later to resolve the issue. As a temporary workaround, consider restricting access to protected REST API endpoints until the update is applied.

Exploit

Fix

RCE

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2021-25036

Affected Products

All In One Seo