All In One SEO Pack <= 4.8.7.1 - Missing Authorization
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
Minimum safe version
4.9.3
Update to 4.9.3 or later to address 38 fixable vulnerabilities
All In One SEO Pack <= 4.8.7.1 - Authenticated (Contributor+) Sensitive Information Exposure
CVE-2025-14384
CVE-2025-64295
CVE-2025-67950
CVE-2025-12847
WordPress All In One SEO Pack Plugin <= 4.8.1.1 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-3368
CVE-2024-3554
WordPress All In One SEO Pack Plugin <= 4.2.9 is vulnerable to Cross Site Scripting (XSS)
WordPress All In One SEO Pack Plugin <= 4.2.9 is vulnerable to Cross Site Scripting (XSS)
All in One SEO <= 2.1.5 - Missing Authorization
All in One SEO <= 2.1.5 - Cross-Site Scripting
All in One SEO <= 2.2.4.1 - Privilege Escalation to Arbitrary Post Modification
All in One SEO <= 2.2.6.1 - Reflected Cross-Site Scripting
All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic <= 2.3.6 - Stored Cross-Site Scripting
All in One SEO Pack <= 2.3.7 - Unauthenticated Stored Cross-Site Scripting
All in One SEO <= 2.9.1.1 - Authenticated Stored Cross-Site Scripting
All in One SEO Pack <= 2.1.5 - Unspecified Privilege Escalation
All in One SEO Pack <= 2.1.5 - aioseop_functions.php new_meta Parameter XSS
wpscan.com
All in One SEO Pack <= 2.3.6.1 - Unauthenticated Stored Cross-Site Scripting (XSS)
All in One SEO Pack <= 2.3.7 - Unauthenticated Stored Cross-Site Scripting (XSS)
All in One SEO Pack <= 2.9.1.1 - Authenticated Stored Cross-Site Scripting (XSS)
CVE-2022-38093
WordPress All in One SEO Pack Plugin <= 2.1.5 - Privilege Escalation
WordPress All in One SEO Pack Plugin <= 2.1.5 - Cross Site Scripting
WordPress All in One SEO Pack Plugin <= 2.2.6.1 - Cross Site Scripting
WordPress All in One SEO Pack Plugin 2.3.6.1 - Persistent XSS
WordPress All in One SEO Pack Plugin <= 2.3.7 - Cross Site Scripting
WordPress All in One SEO Pack Plugin <= 2.3.6.1 - Stored Cross Site Scripting
CVE-2015-0902
CVE-2019-16520
CVE-2013-5988
CVE-2020-35946
CVE-2021-24307
CVE-2021-25037
CVE-2021-25036