SecAlerts
a

aioseo

Security Risk Profile

35
/100
low

Security Risk Score

Comprehensive risk assessment based on 12 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from May 24, 2021 to present

12
Total CVEs
3
Critical+High
0
Exploited
1
Unpatched

Threat Assessment

Avg CVSS
6.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
35/100
low

Severity Distribution

Critical
1
High
2
Medium
9
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
1

Age Distribution

Common Weaknesses (CWE)

1
XSS
5
2
SQL Injection
2
3
SSRF
1
4
CSRF
1

Most Affected Products

1. aioseo All In One Seo Wordpress10
2. aioseo Broken Link Checker2
3. All in One SEO All in One SEO Pack1
4. All in One SEO All in One SEO WordPress plugin1
5. All in One SEO All in One SEO1

Recent Vulnerabilities

See more →
CVE-2025-11734
CVSS 5.4medium

Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links <= 1.2.5 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Trashing

Nov 18, 2025🔧 No Patch
CVE-2025-2892
CVSS 6.4medium

All in One SEO Pack <= 4.8.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta Description and Canonical URL

May 19, 2025
CVE-2025-1264
CVSS 6.5medium

Broken Link Checker by AIOSEO <= 1.2.3 - Authenticated (Contributor+) SQL Injection

Apr 6, 2025🔧 No Patch
CVE-2024-3368
CVSS 6.1medium

All in One SEO < 4.6.1.1 - Contributor+ Stored XSS

May 20, 2024🔧 No Patch
CVE-2024-3554
CVSS 6.4EPSS 0%medium

All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic <= 4.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

May 2, 2024
CVE-2023-0586
CVSS 6.4medium

All in One SEO Pack <= 4.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Feb 24, 2023🔧 No Patch
CVE-2023-0585
CVSS 4.8medium

All in One SEO Pack <= 4.2.9 - Authenticated (Administrator+) Stored Cross-Site Scripting

Feb 24, 2023🔧 No Patch
CVE-2022-42494
CVSS 6.5medium

WordPress All in One SEO Pro plugin <= 4.2.5.1 - Server Side Request Forgery (SSRF) vulnerability

Nov 8, 2022🔧 No Patch
CVE-2022-38093
CVSS 8.8high

WordPress All in One SEO plugin <= 4.2.3.1 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities

Sep 9, 2022
CVE-2021-25037
CVSS 6.5medium

All In One SEO < 4.1.5.3 - Authenticated SQL Injection

Jan 17, 2022

Monitor aioseo in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

aioseo Security Vulnerabilities & Risk Score | 12 CVEs | SecAlerts - SecAlerts