All In One SEO Pack <= 3.2.6 - Stored Cross-Site Scripting
2019-10-16 00:00
Tobias FinkStrategic Overview
StatusPatched in 3.2.7
Affected PluginAll in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)
Affected Version
<= 3.2.6CVSS6.4Medium
CVE
CVE-2019-16520Vulnerability Overview
The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to improper encoding of the SEO-specific description for posts provided by the plugin via unsafe placeholder replacement.
Technical Analysis
REMEDIATION: Update to version 3.2.7, or a newer patched version --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C