CVE-2021-24307
The All in One SEO plugin before version 4.1.0.2 contains a code execution vulnerability affecting authenticated users holding the aioseo_tools_settings capability, typically administrators. When users import a backup configuration file through the Tools section, the plugin deserializes the .ini file contents without proper sanitization. By leveraging the bundled Monolog library, an attacker can construct a malicious serialized object that executes arbitrary system commands during the unserialization process. While this requires administrative-level access, the vulnerability becomes particularly dangerous on shared hosting environments where the hosting provider has disabled direct file modifications through WordPress configuration.
Based on public CVE data (MITRE/NVD).