The All in One SEO WordPress plugin before 4.6.1.1 does not validate and escape some of its Post fields before outputting them back, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Metrics
Affected Vendors & Products
References
History
Fri, 14 Mar 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Aioseo
Aioseo all In One Seo |
|
CPEs | cpe:2.3:a:aioseo:all_in_one_seo:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Aioseo
Aioseo all In One Seo |
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-03-14T17:20:36.410Z
Reserved: 2024-04-05T08:51:06.596Z
Link: CVE-2024-3368

Updated: 2024-08-01T20:05:08.481Z

Status : Awaiting Analysis
Published: 2024-05-20T06:15:08.527
Modified: 2025-03-14T18:15:28.580
Link: CVE-2024-3368

No data.