CVE-2013-5988: XSS
Published Feb 11, 2020
·Updated
A Cross-site Scripting (XSS) vulnerability exists in the All in One SEO Pack plugin before 2.0.3.1 for WordPress via the Search parameter.
Affected Software
2 affected components
Semperplugins All In One Seo Pack Wordpress>=1.3.6.4<=1.6.15.2
Semperplugins All In One Seo Pack Wordpress>=2.0<2.0.3.1
Event History
Feb 11, 2020
CVE Published
via MITRE·05:40 PM
Data Sourced
via MITRE·05:40 PM
Description
Frequently Asked Questions
1
What is CVE-2013-5988?
CVE-2013-5988 is a Cross-site Scripting (XSS) vulnerability in the All in One SEO Pack plugin for WordPress.
2
How severe is CVE-2013-5988?
CVE-2013-5988 has a severity rating of 6.1 (medium).
3
How does CVE-2013-5988 impact the All in One SEO Pack plugin?
CVE-2013-5988 allows an attacker to inject malicious code into the Search parameter, which can potentially be executed by users of the plugin.
4
Which versions of the All in One SEO Pack plugin are affected by CVE-2013-5988?
Versions before 2.0.3.1 are affected by CVE-2013-5988.
5
How can I fix CVE-2013-5988?
To fix CVE-2013-5988, it is recommended to update the All in One SEO Pack plugin to version 2.0.3.1 or later.