CVE · Medium

CVE-2025-64295 — All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.8.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-64295 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.8.7 Insertion of Sensitive Information Into Sent Data Medium 6.5 < 4.8.7 4.8.7 2025-11-26

CVE-2025-64295

The All in One SEO plugin for WordPress contains a flaw that allows authorized users with at least Subscriber privileges to obtain confidential information about other users or the site's settings, affecting all versions up to 4.8.6.1. This vulnerability enables attackers to gather sensitive details from within the system.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.