cleantalk
Vulnerabilities and Security Researches

All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic, 8327743a0a9105aea318021a17da44155e980487

Published on
May 31, 2014
Research Description
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings &amp; Increase Traffic [all-in-one-seo-pack] < 2.1.6 All in One SEO <= 2.1.5 - Missing Authorization The All in One SEO plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the aioseop_ajax_save_meta() function in versions up to, and including, 2.1.5. This makes it possible for authenticated attackers with subscriber level permissions and above to modify some of the SEO settings of the plugin for any given post.
Affected versions
max 2.1.6.
Status
vulnerable