CVE · Medium

CVE-2021-25037 — All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.1.5.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-25037 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.1.5.3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 6.5 < 4.1.5.3 4.1.5.3 2021-12-14

CVE-2021-25037

The All in One SEO plugin prior to version 4.1.5.3 contains a SQL injection vulnerability that requires authentication to exploit. An attacker with authenticated access could leverage this flaw to query the site's database and potentially retrieve sensitive data including user credentials and password hashes. The vulnerability was identified through an internal security audit conducted by the Jetpack Scan team.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.