First published: Fri Sep 09 2022(Updated: )
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in All in One SEO plugin <= 4.2.3.1 at WordPress.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
All In One SEO Pack | <=4.2.3.1 |
Update to 4.2.4 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-38093 is considered high with a severity value of 8.8.
CVE-2022-38093 refers to multiple Cross-Site Request Forgery (CSRF) vulnerabilities in the All in One SEO plugin version 4.2.3.1 or earlier at WordPress.
The All in One SEO plugin versions up to and including 4.2.3.1 at WordPress are affected by CVE-2022-38093.
CVE-2022-38093 is associated with CWE-352 (Cross-Site Request Forgery).
To fix CVE-2022-38093, update the All in One SEO plugin to a version later than 4.2.3.1.