CVE Database /
CVE-2025-64295
CVE · Medium
CVE-2025-64295 — All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.8.7
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-64295
|
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.8.7 |
Insertion of Sensitive Information Into Sent Data |
Medium
6.5
|
< 4.8.7
|
4.8.7 |
2025-11-26 |
—
|
CVE-2025-64295
The All in One SEO plugin for WordPress contains a flaw that allows authorized users with at least Subscriber privileges to obtain confidential information about other users or the site's settings, affecting all versions up to 4.8.6.1. This vulnerability enables attackers to gather sensitive details from within the system.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings