WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: all-in-one-seo-pack

Estado de mantenimiento

  • Última versión conocida: 4.9.10

Vulnerabilidades conocidas

21 CVEs conocidos registrados para All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights).

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-5075 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.9.7.1 Exposición de información sensible a un actor no autorizado Media 4,3 < 4.9.7.1 4.9.7.1 2026-05-19 ✓ corregido en la última versión
CVE-2025-14384 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.9.3 Falta de control de autorización Media 4,3 < 4.9.3 4.9.3 2026-01-15 ✓ corregido en la última versión
CVE-2025-67950 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.9.1.1 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Alta 8,5 < 4.9.1.1 4.9.1.1 2025-12-06 ✓ corregido en la última versión
CVE-2025-64295 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.8.7 Inserción de información sensible en los datos enviados Media 6,5 < 4.8.7 4.8.7 2025-11-26 ✓ corregido en la última versión
CVE-2025-12847 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.9.0 Falta de control de autorización Media 4,3 < 4.9.0 4.9.0 2025-11-14 ✓ corregido en la última versión
CVE-2025-58650 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.8.7.2 Media 5,4 < 4.8.7.2 4.8.7.2 2025-09-22 ✓ corregido en la última versión
CVE-2024-3554 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.6.1.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 4.6.1.1 4.6.1.1 2024-04-29 ✓ corregido en la última versión
CVE-2024-3368 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.6.1.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 4.6.1.1 4.6.1.1 2024-04-29 ✓ corregido en la última versión

CVE-2026-5075

The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'internalOptions' localized script data in versions up to, and including, 4.9.7 due to sensitive internal option data being passed to wp_localize_script() in post editor contexts without effective masking for low-privilege users. This makes it possible for authenticated attackers, with contributor-level access and above, to view configured API/OAuth tokens and license-related values from page source.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-14384

The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `/aioseo/v1/ai/credits` REST route in all versions up to, and including, 4.9.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to disclose the global AI access token.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-67950

The All In One SEO Pack plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-64295

The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.8.6.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-12847

The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to unauthorized arbitrary media attachment deletion due to a missing authorization check in all versions up to, and including, 4.8.9. This is due to the REST API endpoint `/wp-json/aioseo/v1/ai/image-generator` only verifying that users have the `edit_posts` capability (Contributors and above) without checking if they own or have permission to delete the specific media attachments. This makes it possible for authenticated attackers, with Contributor-level access and above, to permanently delete arbitrary media attachments by ID via the REST API, granted they can determine valid attachment IDs.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-58650

The All In One SEO Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.8.7.1. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-3554

The All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-3368

The All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the meta description in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

+ 39 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2023-0586 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.3.0 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 4.3.0 4.3.0 2023-02-24 ✓ corregido en la última versión
CVE-2023-0585 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.3.0 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 4.3.0 4.3.0 2023-02-24 ✓ corregido en la última versión
CVE-2022-38093 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.2.4 Falsificación de petición en sitios cruzados (CSRF) Media 5,4 < 4.2.4 4.2.4 2022-09-05 ✓ corregido en la última versión
CVE-2021-25036 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.1.5.3 Manejo incorrecto de la distinción entre mayúsculas y minúsculas Alta 8,8 < 4.1.5.3 4.1.5.3 2021-12-14 ✓ corregido en la última versión
CVE-2021-25037 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.1.5.3 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Media 6,5 < 4.1.5.3 4.1.5.3 2021-12-14 ✓ corregido en la última versión
CVE-2021-24307 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.1.0.2 Deserialización de datos no confiables Alta 8,8 < 4.1.0.2 4.1.0.2 2021-05-09 ✓ corregido en la última versión
CVE-2020-35946 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 3.6.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.6.2 3.6.2 2020-07-16 ✓ corregido en la última versión
CVE-2019-16520 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 3.2.7 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 3.2.7 3.2.7 2019-10-16 ✓ corregido en la última versión
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.10 Desconocido < 2.10 2.10 2018-10-18 ✓ corregido en la última versión
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.3.7 Desconocido < 2.3.7 2.3.7 2016-07-19 ✓ corregido en la última versión
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.3.8 Desconocido < 2.3.8 2.3.8 2016-07-19 ✓ corregido en la última versión
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.3.8 Desconocido < 2.3.8 2.3.8 2016-07-13 ✓ corregido en la última versión
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.3.6.2 Desconocido < 2.3.6.2 2.3.6.2 2016-07-11 ✓ corregido en la última versión
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.3.7 Desconocido < 2.3.7 2.3.7 2016-07-01 ✓ corregido en la última versión
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.2.6.2 Desconocido < 2.2.6.2 2.2.6.2 2015-09-09 ✓ corregido en la última versión
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.1.6 Desconocido < 2.1.6 2.1.6 2015-05-15 ✓ corregido en la última versión
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.1.6 Desconocido < 2.1.6 2.1.6 2015-05-15 ✓ corregido en la última versión
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.2.6.2 Desconocido < 2.2.6.2 2.2.6.2 2015-04-20 ✓ corregido en la última versión
CVE-2015-0902 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.2.6 Exposición de información sensible a un actor no autorizado Desconocido < 2.2.6 2.2.6 2015-01-08 ✓ corregido en la última versión
CVE-2013-5988 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.0.3.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 2.0.3.1 2.0.3.1 2014-08-01 ✓ corregido en la última versión
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.2.5 Desconocido < 2.2.5 2.2.5 2014-05-31 ✓ corregido en la última versión
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.1.6 Desconocido < 2.1.6 2.1.6 2014-05-31 ✓ corregido en la última versión
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.1.6 Desconocido < 2.1.6 2.1.6 2014-05-31 ✓ corregido en la última versión
CVE-2025-2892 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.8.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 4.8.2 4.8.2 0000-00-00 ✓ corregido en la última versión
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.8.7.2 Media 4,3 < 4.8.7.2 4.8.7.2 0000-00-00 ✓ corregido en la última versión
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.10 Desconocido < 2.10 2.10 ✓ corregido en la última versión
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.3.8 Desconocido < 2.3.8 2.3.8 ✓ corregido en la última versión
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.3.7 Desconocido < 2.3.7 2.3.7 ✓ corregido en la última versión
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.2.6.2 Desconocido < 2.2.6.2 2.2.6.2 ✓ corregido en la última versión
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.1.6 Desconocido < 2.1.6 2.1.6 ✓ corregido en la última versión
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.1.6 Desconocido < 2.1.6 2.1.6 ✓ corregido en la última versión
All in One SEO Pack <= 2.1.5 - aioseop_functions.php new_meta Parameter XSS Desconocido < 2.1.6 2.1.6 ✓ corregido en la última versión
All in One SEO Pack <= 2.1.5 - Unspecified Privilege Escalation Desconocido < 2.1.6 2.1.6 ✓ corregido en la última versión
All in One SEO Pack <= 2.2.6.1 - Cross-Site Scripting (XSS) Desconocido < 2.2.6.2 2.2.6.2 ✓ corregido en la última versión
All in One SEO Pack < 2.3.7 - Unauthenticated Stored Cross-Site Scripting (XSS) Desconocido < 2.3.7 2.3.7 ✓ corregido en la última versión
All in One SEO Pack <= 2.3.7 - Unauthenticated Stored Cross-Site Scripting (XSS) Desconocido < 2.3.8 2.3.8 ✓ corregido en la última versión
All in One SEO Pack < 2.10 - Authenticated Stored Cross-Site Scripting (XSS) Desconocido < 2.10 2.10 ✓ corregido en la última versión
CVE-2025-58649 All In One SEO Pack < 4.8.7.2 - Contributor+ Sensitive Information Exposure Desconocido < 4.8.7.2 4.8.7.2 ✓ corregido en la última versión
CVE-2026-10755 All in One SEO < 4.9.9 – Contributor+ Incorrect Authorization via AI Integration Desconocido < 4.9.9 4.9.9 ✓ corregido en la última versión

CVE-2023-0586

Update the WordPress All In One SEO Pack plugin to the latest available version (at least 4.3.0). Ivan Kuzymchak discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress All In One SEO Pack Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 4.3.0.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-0585

Update the WordPress All In One SEO Pack plugin to the latest available version (at least 4.3.0). WordFence discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress All In One SEO Pack Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 4.3.0.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2022-38093

The All in One SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.3.1. This is due to missing or incorrect nonce validation on several of its functions. This makes it possible for unauthenticated attackers to execute them, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2021-25036

The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may grant bad actors access to protected REST API endpoints they shouldn’t have access to. This could ultimately enable users with low-privileged accounts, like subscribers, to perform remote code execution on affected sites.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-25037

The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to privileged information from the affected site’s database (e.g., usernames and hashed passwords).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-24307

The plugin enables authenticated users with "aioseo_tools_settings" privilege (most of the time admin) to execute arbitrary code on the underlying host. Users can restore plugin's configuration by uploading a backup .ini file in the section "Tool > Import/Export". However, the plugin attempts to unserialize values of the .ini file. Moreover, the plugin embeds Monolog library which can be used to craft a gadget chain and thus trigger system command execution. As exploitation requires high privileges, the main threat scenario concerns attackers willing to compromise system host on mutualized wordpress platform where plugin installation has been denied by security hardening by hosting provider (DISALLOW_FILE_MODS=true in config).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

CVE-2020-35946

An issue was discovered in the All in One SEO Pack plugin before 3.6.2 for WordPress. The SEO Description and Title fields are vulnerable to unsanitized input from a Contributor, leading to stored XSS.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2019-16520

The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to improper encoding of the SEO-specific description for posts provided by the plugin via unsafe placeholder replacement.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.10

The All in One SEO plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including 2.9.1.1, via post meta values. This makes it possible for attackers with Contributor level permissions and above to inject arbitrary web scripts in administrative pages that execute whenever a user accesses the page with the stored web scripts.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.3.7

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.3.8

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Upgrade this plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.3.8

The All in One SEO Pack plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting via unspecified vectors that make it possible for attackers to inject arbitrary web scripts into web pages that will execute when a victim accesses the page in versions up to, and including, 2.3.7. Please note that this exploit only works if the user has enabled the sitemap module in the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.3.6.2

Because of this vulnerability, an attacker can steal administrators session token or perform other arbitrary actions. Update the WordPress plugin to the newer stable and safe version.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.3.7

The All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP_REFERER header in versions up to, and including, 2.3.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.2.6.2

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Upgrade the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.1.6

This plugin is prone to a cross site scripting vulnerability via aioseop_functions.php new_meta parameter. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.1.6

This plugin is prone to an unspecified privilege escalation vulnerability. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.2.6.2

The All in One SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.2.6.1 due to insufficient input sanitization and output escaping on add_query_arg and remove_query_arg. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2015-0902

All in One SEO Pack is a WordPress plugin. All in One SEO Pack automatically adds a meta tag ("Meta Description") to a page using some part of its contents, and this behavior is enabled in the initial configuration. Meta Description can be added even when a page is password-protected, therefore some part of its contents are not protected. Fumito MIZUNO of rescuework.inc reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: jvndb.jvn.jp

CVE-2013-5988

A Cross-site Scripting (XSS) vulnerability exists in the All in One SEO Pack plugin before 2.0.3.1 for WordPress via the Search parameter.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.2.5

The All in One SEO plugin for WordPress is vulnerable to Authenticated Privilege Escalation leading to Post Changes in versions up to, and including, 2.2.4.1. This is due to certain actions being available to low-privileged users. This makes it possible for Subscriber-level attackers to add or modify certain parameters used by the plugin. This includes the post’s SEO title, description and keyword meta tags. This could be used to decrease a site's Search Engine Results Page (SERP) ranking.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.1.6

The All in One SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SEO settings for posts in versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.1.6

The All in One SEO plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the aioseop_ajax_save_meta() function in versions up to, and including, 2.1.5. This makes it possible for authenticated attackers with subscriber level permissions and above to modify some of the SEO settings of the plugin for any given post.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-2892

The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post Meta Description and Canonical URL parameters in all versions up to, and including, 4.8.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.8.7.2

The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.8.7.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.10

The All in One SEO Pack WordPress plugin was affected by an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.3.8

The All in One SEO Pack WordPress plugin was affected by a Unauthenticated Stored Cross-Site Scripting (XSS) security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.3.7

Requires 'Track Blocked Bots setting' to be enabled which it is not by default.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.1.6

The All in One SEO Pack WordPress plugin was affected by an aioseop_functions.php new_meta Parameter XSS security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 2.1.6

The All in One SEO Pack WordPress plugin was affected by an Unspecified Privilege Escalation security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén All in One SEO – AI SEO Plugin to Boost SEO Rankings &amp; Traffic (Schema, Local SEO, Sitemap &amp; SEO Insights) actualizado — 4.9.10 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.