All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic, a32fbfc28c93ef3110ed89cda027e1f3df613f67
- CVE, Research URL
- Home page URL
- Application
-
All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic
- Published on
- Jul 13, 2016
- Research Description
- All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic [all-in-one-seo-pack] < 2.3.8 All in One SEO Pack <= 2.3.7 - Unauthenticated Stored Cross-Site Scripting The All in One SEO Pack plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting via unspecified vectors that make it possible for attackers to inject arbitrary web scripts into web pages that will execute when a victim accesses the page in versions up to, and including, 2.3.7. Please note that this exploit only works if the user has enabled the sitemap module in the plugin.
- Affected versions
-
max 2.3.8.
- Status
-
vulnerable