All in One SEO <= 2.1.5 - Missing Authorization
2014-05-31 00:00
Marc-Alexandre MontpasStrategic Overview
StatusPatched in 2.1.6
Affected PluginAll in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)
Affected Version
<= 2.1.5CVSS6.3Medium
CVE
N/AVulnerability Overview
The All in One SEO plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the aioseop_ajax_save_meta() function in versions up to, and including, 2.1.5. This makes it possible for authenticated attackers with subscriber level permissions and above to modify some of the SEO settings of the plugin for any given post.
Technical Analysis
REMEDIATION: Update to version 2.1.6, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C