All in One SEO <= 2.2.5.1 - Information Disclosure
2015-03-31 00:00
Fumito MIZUNOStrategic Overview
StatusPatched in 2.2.6
Affected PluginAll in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)
Affected Version
< 2.2.6CVSS5.3Medium
CVE
CVE-2015-0902Vulnerability Overview
The Semper Fi All in One SEO Pack plugin before 2.2.6 for WordPress does not consider the presence of password protection during generation of the Meta Description field, which allows remote attackers to obtain sensitive information by reading HTML source code.
Technical Analysis
REMEDIATION: Update to version 2.2.6, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C