CVE-2020-35946: XSS
An issue was discovered in the All in One SEO Pack plugin before 3.6.2 for WordPress. The SEO Description and Title fields are vulnerable to unsanitized input from a Contributor, leading to stored XSS.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of the All in One SEO Pack plugin vulnerability?
The vulnerability ID of the All in One SEO Pack plugin vulnerability is CVE-2020-35946.
What is the severity of CVE-2020-35946?
The severity of CVE-2020-35946 is medium with a severity value of 5.4.
What is the affected software of CVE-2020-35946?
The affected software of CVE-2020-35946 is the All in One SEO Pack plugin version up to 3.6.2 for WordPress.
What is the impact of CVE-2020-35946?
CVE-2020-35946 has a stored XSS impact, allowing unsanitized input from a Contributor affecting the SEO Description and Title fields.
Where can I find more information about CVE-2020-35946?
You can find more information about CVE-2020-35946 at the following references: [wpscan.com](https://wpscan.com/vulnerability/10320) and [wordfence.com](https://www.wordfence.com/blog/2020/07/2-million-users-affected-by-vulnerability-in-all-in-one-seo-pack/).