CVE-2019-16520: XSS
The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to improper encoding of the SEO-specific description for posts provided by the plugin via unsafe placeholder replacement.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability CVE-2019-16520?
The vulnerability CVE-2019-16520 is a stored cross-site scripting (XSS) vulnerability in the All in One SEO Pack plugin for WordPress.
How does the vulnerability CVE-2019-16520 affect WordPress?
The vulnerability CVE-2019-16520 affects the All in One SEO Pack plugin for WordPress, allowing an attacker to execute malicious scripts on affected websites.
What is the severity of CVE-2019-16520?
The severity of CVE-2019-16520 is rated as medium with a CVSS score of 5.4.
How can I fix the vulnerability CVE-2019-16520?
To fix the vulnerability CVE-2019-16520, update the All in One SEO Pack plugin to version 3.2.7 or later.
Where can I find more information about the vulnerability CVE-2019-16520?
You can find more information about the vulnerability CVE-2019-16520 in the references provided: [link1], [link2], [link3].