Description
WordPress Plugin All in One SEO-Best WordPress SEO-Easily Improve SEO Rankings & Increase Traffic is prone to multiple vulnerabilities, including SQL injection and privilege escalation vulnerabilities. Exploiting these issues may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database, or to perform otherwise restricted actions and subsequently access protected REST API endpoints. WordPress Plugin All in One SEO-Best WordPress SEO-Easily Improve SEO Rankings & Increase Traffic versions between 4.0.0 - 4.1.5.2 and 4.1.3.1 - 4.1.5.2 (inclusively) are vulnerable.
Remediation
Update to plugin version 4.1.5.3 or latest
References
Related Vulnerabilities
Joomla Generation of Error Message Containing Sensitive Information Vulnerability (CVE-2018-11325)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-6403)
WordPress Plugin S3 Video Cross-Site Scripting (0.97)
OpenVPN AS Improper Authentication Vulnerability (CVE-2020-8953)