Extension WordPress
Vulnérabilités All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)
Cette page rassemble les failles publiées pour All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)
27 fiches
All in One SEO <= 4.9.7 – Authenticated (Contributor+) Sensitive Information Exposure via 'internalOptions' Localized Script Data
The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'internalOptions' localized script data in versions up to, and including, 4.9.7 due to sensitive internal option data being passed to wp_localize_script() in post…
*-4.9.7
4.9.7.1
19/05/2026
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.9.2 – Missing Authorization to Authenticated (Contributor+) AI Access Token and Credit Disclosure
The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `/aioseo/v1/ai/credits` REST route in…
*-4.9.2
4.9.3
15/01/2026
All In One SEO Pack <= 4.9.1 – Authenticated (Contributor+) SQL Injection
The All In One SEO Pack plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
*-4.9.1
4.9.1.1
06/12/2025
All In One SEO Pack <= 4.8.6.1 – Authenticated (Subscriber+) Information Exposure
The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.8.6.1. This makes it possible for…
*-4.8.6.1
4.8.7
26/11/2025
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.8.9 – Missing Authorization to Authenticated (Contributor+) Arbitrary Media Deletion
The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to unauthorized arbitrary media attachment deletion due to a missing authorization check in all versions up to,…
*-4.8.9
4.9.0
14/11/2025
All In One SEO Pack <= 4.8.7.1 – Authenticated (Contributor+) Sensitive Information Exposure
The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.8.7.1. This makes it possible for…
*-4.8.7.1
4.8.7.2
22/09/2025
All In One SEO Pack <= 4.8.7.1 – Missing Authorization
The All In One SEO Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.8.7.1. This makes it possible for authenticated attackers, with…
*-4.8.7.1
4.8.7.2
22/09/2025
All in One SEO Pack <= 4.8.1.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta Description and Canonical URL
The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post Meta Description and Canonical URL parameters in all versions up…
*-4.8.1.1
4.8.2
18/05/2025
All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic <= 4.6.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including,…
*-4.6.0
4.6.1.1
29/04/2024
All in One SEO <= 4.6.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the meta description in all versions up to, and including,…
*-4.6.0
4.6.1.1
29/04/2024
All in One SEO Pack <= 4.2.9 – Authenticated (Administrator+) Stored Cross-Site Scripting
The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input sanitization and output escaping. This makes it possible for…
*-4.2.9
4.3.0
24/02/2023
All in One SEO Pack <= 4.2.9 – Authenticated (Contributor+) Stored Cross-Site Scripting
The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input sanitization and output escaping. This makes it possible for…
*-4.2.9
4.3.0
24/02/2023
All in One SEO <= 4.2.3.1 – Cross-Site Request Forgery
The All in One SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.3.1. This is due to missing or incorrect nonce validation on several of its functions. This makes it…
*-4.2.3.1
4.2.4
05/09/2022
All in One SEO 4.1.3.1 – 4.1.5.2 – Authenticated SQL Injection
The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to privileged information from…
4.1.3.1-4.1.5.2
4.1.5.3
14/12/2021
All in One SEO 4.0.0 – 4.1.5.2 Authorization Bypass
The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may grant bad actors access to protected REST API…
4.0.0-4.1.5.2
4.1.5.3
14/12/2021
All in One SEO <= 4.1.0.1 – Authenticated Code Injection
The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the time admin) to execute arbitrary code on the underlying host. Users…
[*, 4.1.0.2)
4.1.0.2
09/05/2021
All in One SEO Pack <= 3.6.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
An issue was discovered in the All in One SEO Pack plugin before 3.6.2 for WordPress. The SEO Description and Title fields are vulnerable to unsanitized input from a Contributor, leading to stored XSS.
[*, 3.6.2)
3.6.2
16/07/2020
All In One SEO Pack <= 3.2.6 – Stored Cross-Site Scripting
The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to improper encoding of the SEO-specific description for posts provided by the plugin via unsafe placeholder replacement.
*-3.2.6
3.2.7
16/10/2019
All in One SEO <= 2.9.1.1 – Authenticated Stored Cross-Site Scripting
The All in One SEO plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including 2.9.1.1, via post meta values. This makes it possible for attackers with Contributor level permissions and above to…
[*, 2.10)
2.10
18/10/2018
All in One SEO Pack <= 2.3.7 – Unauthenticated Stored Cross-Site Scripting
The All in One SEO Pack plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting via unspecified vectors that make it possible for attackers to inject arbitrary web scripts into web pages that will execute when a…
[*, 2.3.8)
2.3.8
13/07/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.