Extension WordPress
Vulnérabilités All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights), page 2
Cette page rassemble les failles publiées pour All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)
27 fiches
All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic <= 2.3.6 – Stored Cross-Site Scripting
The All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP_REFERER header in versions up to, and including, 2.3.6…
[*, 2.3.7)
2.3.7
01/07/2016
All in One SEO <= 2.2.6.1 – Reflected Cross-Site Scripting
The All in One SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2.6.1 due to insufficient input sanitization and output escaping on add_query_arg and remove_query_arg. This makes it possible for…
[*, 2.2.6.2)
2.2.6.2
20/04/2015
All in One SEO <= 2.2.5.1 – Information Disclosure
The Semper Fi All in One SEO Pack plugin before 2.2.6 for WordPress does not consider the presence of password protection during generation of the Meta Description field, which allows remote attackers to obtain sensitive information by reading…
[*, 2.2.6)
2.2.6
31/03/2015
All in One SEO <= 2.0.3 – Cross-Site Scripting via Search Parameter
A Cross-site Scripting (XSS) vulnerability exists in the All in One SEO Pack plugin before 2.0.3.1 for WordPress via the Search parameter.
*-2.0.3
2.0.3.1
01/08/2014
All in One SEO <= 2.2.4.1 – Privilege Escalation to Arbitrary Post Modification
The All in One SEO plugin for WordPress is vulnerable to Authenticated Privilege Escalation leading to Post Changes in versions up to, and including, 2.2.4.1. This is due to certain actions being available to low-privileged users. This makes…
*-2.2.4.1
2.2.5
31/05/2014
All in One SEO <= 2.1.5 – Cross-Site Scripting
The All in One SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SEO settings for posts in versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it…
*-2.1.5
2.1.6
31/05/2014
All in One SEO <= 2.1.5 – Missing Authorization
The All in One SEO plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the aioseop_ajax_save_meta() function in versions up to, and including, 2.1.5. This makes it possible for authenticated attackers with…
*-2.1.5
2.1.6
31/05/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.