Extension WordPress

Vulnérabilités All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

Cette page rassemble les failles publiées pour All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights), leurs plages de versions affectées et les correctifs signalés dans la base locale.

27Vulnérabilités
1Critiques
27Avec correctif
9,6CVSS maximal

Historique de sécurité

CVE et vulnérabilités de All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

27 fiches

CVE-2026-5075 Moyenne · 4,3
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO <= 4.9.7 – Authenticated (Contributor+) Sensitive Information Exposure via 'internalOptions' Localized Script Data

The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'internalOptions' localized script data in versions up to, and including, 4.9.7 due to sensitive internal option data being passed to wp_localize_script() in post…

Versions affectées

*-4.9.7

Correctif

4.9.7.1

Publication

19/05/2026

CVE-2025-14384 Moyenne · 4,3
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.9.2 – Missing Authorization to Authenticated (Contributor+) AI Access Token and Credit Disclosure

The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `/aioseo/v1/ai/credits` REST route in…

Versions affectées

*-4.9.2

Correctif

4.9.3

Publication

15/01/2026

CVE-2025-67950 Moyenne · 6,5
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All In One SEO Pack <= 4.9.1 – Authenticated (Contributor+) SQL Injection

The All In One SEO Pack plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

Versions affectées

*-4.9.1

Correctif

4.9.1.1

Publication

06/12/2025

CVE-2025-64295 Moyenne · 4,3
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All In One SEO Pack <= 4.8.6.1 – Authenticated (Subscriber+) Information Exposure

The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.8.6.1. This makes it possible for…

Versions affectées

*-4.8.6.1

Correctif

4.8.7

Publication

26/11/2025

CVE-2025-12847 Moyenne · 4,3
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.8.9 – Missing Authorization to Authenticated (Contributor+) Arbitrary Media Deletion

The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to unauthorized arbitrary media attachment deletion due to a missing authorization check in all versions up to,…

Versions affectées

*-4.8.9

Correctif

4.9.0

Publication

14/11/2025

CVE-2025-58649 Moyenne · 4,3
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All In One SEO Pack <= 4.8.7.1 – Authenticated (Contributor+) Sensitive Information Exposure

The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.8.7.1. This makes it possible for…

Versions affectées

*-4.8.7.1

Correctif

4.8.7.2

Publication

22/09/2025

CVE-2025-58650 Moyenne · 5,4
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All In One SEO Pack <= 4.8.7.1 – Missing Authorization

The All In One SEO Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.8.7.1. This makes it possible for authenticated attackers, with…

Versions affectées

*-4.8.7.1

Correctif

4.8.7.2

Publication

22/09/2025

CVE-2025-2892 Moyenne · 6,4
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO Pack <= 4.8.1.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta Description and Canonical URL

The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post Meta Description and Canonical URL parameters in all versions up…

Versions affectées

*-4.8.1.1

Correctif

4.8.2

Publication

18/05/2025

CVE-2024-3554 Moyenne · 6,4
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic <= 4.6.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including,…

Versions affectées

*-4.6.0

Correctif

4.6.1.1

Publication

29/04/2024

CVE-2024-3368 Moyenne · 6,4
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO <= 4.6.0 – Authenticated (Contributor+) Stored Cross-Site Scripting

The All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the meta description in all versions up to, and including,…

Versions affectées

*-4.6.0

Correctif

4.6.1.1

Publication

29/04/2024

CVE-2023-0585 Moyenne · 4,4
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO Pack <= 4.2.9 – Authenticated (Administrator+) Stored Cross-Site Scripting

The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-4.2.9

Correctif

4.3.0

Publication

24/02/2023

CVE-2023-0586 Moyenne · 6,4
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO Pack <= 4.2.9 – Authenticated (Contributor+) Stored Cross-Site Scripting

The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-4.2.9

Correctif

4.3.0

Publication

24/02/2023

CVE-2022-38093 Élevée · 8,8
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO <= 4.2.3.1 – Cross-Site Request Forgery

The All in One SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.3.1. This is due to missing or incorrect nonce validation on several of its functions. This makes it…

Versions affectées

*-4.2.3.1

Correctif

4.2.4

Publication

05/09/2022

CVE-2021-25037 Critique · 9,6
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO 4.1.3.1 – 4.1.5.2 – Authenticated SQL Injection

The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to privileged information from…

Versions affectées

4.1.3.1-4.1.5.2

Correctif

4.1.5.3

Publication

14/12/2021

CVE-2021-25036 Élevée · 8,8
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO 4.0.0 – 4.1.5.2 Authorization Bypass

The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may grant bad actors access to protected REST API…

Versions affectées

4.0.0-4.1.5.2

Correctif

4.1.5.3

Publication

14/12/2021

CVE-2021-24307 Élevée · 8,8
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO <= 4.1.0.1 – Authenticated Code Injection

The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the time admin) to execute arbitrary code on the underlying host. Users…

Versions affectées

[*, 4.1.0.2)

Correctif

4.1.0.2

Publication

09/05/2021

CVE-2020-35946 Moyenne · 6,4
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO Pack <= 3.6.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

An issue was discovered in the All in One SEO Pack plugin before 3.6.2 for WordPress. The SEO Description and Title fields are vulnerable to unsanitized input from a Contributor, leading to stored XSS.

Versions affectées

[*, 3.6.2)

Correctif

3.6.2

Publication

16/07/2020

CVE-2019-16520 Moyenne · 6,4
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All In One SEO Pack <= 3.2.6 – Stored Cross-Site Scripting

The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to improper encoding of the SEO-specific description for posts provided by the plugin via unsafe placeholder replacement.

Versions affectées

*-3.2.6

Correctif

3.2.7

Publication

16/10/2019

Vulnérabilité Moyenne · 6,4
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO <= 2.9.1.1 – Authenticated Stored Cross-Site Scripting

The All in One SEO plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including 2.9.1.1, via post meta values. This makes it possible for attackers with Contributor level permissions and above to…

Versions affectées

[*, 2.10)

Correctif

2.10

Publication

18/10/2018

Vulnérabilité Élevée · 7,2
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO Pack <= 2.3.7 – Unauthenticated Stored Cross-Site Scripting

The All in One SEO Pack plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting via unspecified vectors that make it possible for attackers to inject arbitrary web scripts into web pages that will execute when a…

Versions affectées

[*, 2.3.8)

Correctif

2.3.8

Publication

13/07/2016

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités