Aioseo
Aioseo ALL IN ONE SEO: vulnerabilidades y CVE
Aioseo ALL IN ONE SEO tiene 17 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses7
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-19856 | Media (6.5) | 0.18% | — | 2 oct 2026 | The All in One SEO WordPress plugin before 5.0.2.1 does not correctly determine which shortcodes are present in content derived from user input before deciding which ones to strip, allowing unauthenticated users to… |
| CVE-2026-85492 | Media (6.1) | 0.21% | — | 2 oct 2026 | The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via URL Pathname in all versions up to,… |
| CVE-2026-82884 | Media (6.8) | 0.43% | — | 2 sept 2026 | The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise and escape some content stored in posts before rendering it back in the post editor, which could allow users with the contributor role and above to… |
| CVE-2026-10755 | Baja (2.7) | 0.28% | — | 20 jul 2026 | The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset… |
| CVE-2026-5075 | Media (4.3) | 0.31% | — | 20 may 2026 | The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'internalOptions' localized script data in versions up to, and including, 4.9.7 due to sensitive internal option data being… |
| CVE-2025-14384 | Media (4.3) | 0.25% | — | 16 ene 2026 | The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `/aioseo/v1/ai/credits` REST… |
| CVE-2025-12847 | Media (4.3) | 0.24% | — | 15 nov 2025 | The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to unauthorized arbitrary media attachment deletion due to a missing authorization check in all… |
| CVE-2025-2892 | Media (5.4) | 0.29% | — | 19 may 2025 | The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post Meta Description and Canonical URL parameters in all… |
| CVE-2024-3368 | Media (6.1) | 0.37% | — | 20 may 2024 | The All in One SEO WordPress plugin before 4.6.1.1 does not validate and escape some of its Post fields before outputting them back, which could allow users with the contributor role and above to perform Stored… |
| CVE-2024-3554 | Media (5.4) | 0.45% | — | 2 may 2024 | The All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and… |
| CVE-2023-0586 | Media (5.4) | 2.5% | — | 24 feb 2023 | The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input sanitization and output escaping. This… |
| CVE-2023-0585 | Media (4.8) | 0.78% | — | 24 feb 2023 | The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input sanitization and output escaping. This… |
| CVE-2022-42494 | Media (6.5) | 0.60% | — | 8 nov 2022 | Server Side Request Forgery (SSRF) vulnerability in All in One SEO Pro plugin <= 4.2.5.1 on WordPress. |
| CVE-2022-38093 | Alta (8.8) | 0.40% | — | 9 sept 2022 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in All in One SEO plugin <= 4.2.3.1 at WordPress. |
| CVE-2021-25037 | Media (6.5) | 1.3% | — | 17 ene 2022 | The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to… |
| CVE-2021-25036 | Alta (8.8) | 3.0% | — | 17 ene 2022 | The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may grant bad actors access to protected REST… |
| CVE-2021-24307 | Alta (8.8) | 53% | — | 24 may 2021 | The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the time admin) to execute arbitrary code on… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.