Extension WordPress

Vulnérabilités All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights), page 2

Cette page rassemble les failles publiées pour All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights), leurs plages de versions affectées et les correctifs signalés dans la base locale.

27Vulnérabilités
1Critiques
27Avec correctif
9,6CVSS maximal

Historique de sécurité

CVE et vulnérabilités de All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

27 fiches

Vulnérabilité Élevée · 7,2
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic <= 2.3.6 – Stored Cross-Site Scripting

The All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP_REFERER header in versions up to, and including, 2.3.6…

Versions affectées

[*, 2.3.7)

Correctif

2.3.7

Publication

01/07/2016

Vulnérabilité Moyenne · 6,1
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO <= 2.2.6.1 – Reflected Cross-Site Scripting

The All in One SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2.6.1 due to insufficient input sanitization and output escaping on add_query_arg and remove_query_arg. This makes it possible for…

Versions affectées

[*, 2.2.6.2)

Correctif

2.2.6.2

Publication

20/04/2015

CVE-2015-0902 Moyenne · 5,3
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO <= 2.2.5.1 – Information Disclosure

The Semper Fi All in One SEO Pack plugin before 2.2.6 for WordPress does not consider the presence of password protection during generation of the Meta Description field, which allows remote attackers to obtain sensitive information by reading…

Versions affectées

[*, 2.2.6)

Correctif

2.2.6

Publication

31/03/2015

Vulnérabilité Moyenne · 4,3
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO <= 2.2.4.1 – Privilege Escalation to Arbitrary Post Modification

The All in One SEO plugin for WordPress is vulnerable to Authenticated Privilege Escalation leading to Post Changes in versions up to, and including, 2.2.4.1. This is due to certain actions being available to low-privileged users. This makes…

Versions affectées

*-2.2.4.1

Correctif

2.2.5

Publication

31/05/2014

Vulnérabilité Moyenne · 6,4
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO <= 2.1.5 – Cross-Site Scripting

The All in One SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SEO settings for posts in versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-2.1.5

Correctif

2.1.6

Publication

31/05/2014

Vulnérabilité Moyenne · 6,3
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

All in One SEO <= 2.1.5 – Missing Authorization

The All in One SEO plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the aioseop_ajax_save_meta() function in versions up to, and including, 2.1.5. This makes it possible for authenticated attackers with…

Versions affectées

*-2.1.5

Correctif

2.1.6

Publication

31/05/2014

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités