CVE · High

CVE-2021-24307 — All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.1.0.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24307 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.1.0.2 Deserialization of Untrusted Data High 8.8 < 4.1.0.2 4.1.0.2 2021-05-09

CVE-2021-24307

The All in One SEO plugin before version 4.1.0.2 contains a code execution vulnerability affecting authenticated users holding the aioseo_tools_settings capability, typically administrators. When users import a backup configuration file through the Tools section, the plugin deserializes the .ini file contents without proper sanitization. By leveraging the bundled Monolog library, an attacker can construct a malicious serialized object that executes arbitrary system commands during the unserialization process. While this requires administrative-level access, the vulnerability becomes particularly dangerous on shared hosting environments where the hosting provider has disabled direct file modifications through WordPress configuration.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.