CVE-2022-38093: WordPress All in One SEO plugin <= 4.2.3.1 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities
Published Sep 9, 2022
·Updated
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in All in One SEO plugin <= 4.2.3.1 at WordPress.
Affected Software
1 affected component
aioseo All In One Seo Wordpress<=4.2.3.1
Remediation
Information
Update to 4.2.4 or higher version.
Event History
Sep 9, 2022
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-38093?
The severity of CVE-2022-38093 is considered high with a severity value of 8.8.
2
What is the description of CVE-2022-38093?
CVE-2022-38093 refers to multiple Cross-Site Request Forgery (CSRF) vulnerabilities in the All in One SEO plugin version 4.2.3.1 or earlier at WordPress.
3
Which software versions are affected by CVE-2022-38093?
The All in One SEO plugin versions up to and including 4.2.3.1 at WordPress are affected by CVE-2022-38093.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-38093?
CVE-2022-38093 is associated with CWE-352 (Cross-Site Request Forgery).
5
How can I fix CVE-2022-38093?
To fix CVE-2022-38093, update the All in One SEO plugin to a version later than 4.2.3.1.