First published: Fri Feb 24 2023(Updated: )
The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Administrator role or above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
All In One SEO Pack | <=4.2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0585 is a vulnerability in the All in One SEO Pack plugin for WordPress that allows authenticated attackers to conduct stored cross-site scripting attacks.
The severity of CVE-2023-0585 is medium with a CVSS score of 4.8.
CVE-2023-0585 affects the All in One SEO Pack plugin for WordPress versions up to 4.2.9 by allowing stored cross-site scripting attacks.
Stored cross-site scripting (XSS) is a type of XSS attack where the malicious script is permanently stored on a target server and is rendered to users when they visit the affected page.
Yes, updating the All in One SEO Pack plugin to a version beyond 4.2.9 will fix the vulnerability.