CVE-2022-42494: WordPress All in One SEO Pro plugin <= 4.2.5.1 - Server Side Request Forgery (SSRF) vulnerability
Published Nov 8, 2022
·Updated
Server Side Request Forgery (SSRF) vulnerability in All in One SEO Pro plugin <= 4.2.5.1 on WordPress.
Affected Software
1 affected component
aioseo All In One Seo Wordpress<=4.2.5.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress All in One SEO Pro pluginto a version that resolves this vulnerability.Fixed in 4.2.6
Event History
Nov 8, 2022
CVE Published
via MITRE·06:33 PM
Data Sourced
via MITRE·06:33 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-42494?
CVE-2022-42494 is a Server Side Request Forgery (SSRF) vulnerability discovered in the All in One SEO Pro plugin for WordPress.
2
What is the severity of CVE-2022-42494?
The severity of CVE-2022-42494 is medium (6.5).
3
How does CVE-2022-42494 affect the All in One SEO Pro plugin?
CVE-2022-42494 affects All in One SEO Pro plugin version 4.2.5.1 and earlier.
4
How can I fix CVE-2022-42494?
To fix CVE-2022-42494, update your All in One SEO Pro plugin to version 4.2.5.2 or newer.
5
Where can I find more information about CVE-2022-42494?
You can find more information about CVE-2022-42494 in the changelog of the All in One SEO Pro plugin and the Patchstack vulnerability database.