CVE · High

CVE-2025-67950 — All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.9.1.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-67950 All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.9.1.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.5 < 4.9.1.1 4.9.1.1 2025-12-06

CVE-2025-67950

The All In One SEO Pack plugin for WordPress contains a security flaw in versions up to 4.9.1, allowing malicious users with contributor-level access or higher to inject unauthorized SQL code into database queries. This occurs because user-submitted data is not properly sanitized, enabling attackers to craft and execute additional SQL commands that can potentially extract sensitive information from the database.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.