PT-2022-9593 · WordPress · All In One Seo
Marc Montpas
·
Published
2022-01-17
·
Updated
2022-10-25
·
CVE-2021-25036
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
All in One SEO WordPress plugin versions prior to 4.1.5.3
Description
The issue allows bad actors to access protected REST API endpoints, potentially enabling users with low-privileged accounts to perform remote code execution on affected sites. This could grant unauthorized access to sensitive areas of the site.
Recommendations
For versions prior to 4.1.5.3, update to version 4.1.5.3 or later to resolve the issue. As a temporary workaround, consider restricting access to protected REST API endpoints until the update is applied.
Exploit
Fix
RCE
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
All In One Seo