CVE Database /
CVE-2021-25037
CVE · Medium
CVE-2021-25037 — All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.1.5.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-25037
|
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.1.5.3 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Medium
6.5
|
< 4.1.5.3
|
4.1.5.3 |
2021-12-14 |
—
|
CVE-2021-25037
The All in One SEO plugin prior to version 4.1.5.3 contains a SQL injection vulnerability that requires authentication to exploit. An attacker with authenticated access could leverage this flaw to query the site's database and potentially retrieve sensitive data including user credentials and password hashes. The vulnerability was identified through an internal security audit conducted by the Jetpack Scan team.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings