Last Updated on 23/12/2021 by Riya
Marc Montpas, an Automattic security expert discovered two flaws in All in One SEO, a powerful WordPress SEO-optimization tool, that, when coupled into an attack chain, might make website owners vulnerable to site acquisition. Over 3 million sites employ the plugin.
Based on the most recent research at Sucuri, an adversary having an account on the site – including a subscriber, shopping account owner, or member – could leverage the power of the weaknesses, which are a privilege-escalation flaw and a SQL-injection vulnerability.
As per Sucuri, the flaws are ideal for the straightforward attack, thus users should switch to the patched version, v. 4.1.5.3.According to Sucuri experts, the flaw “may be leveraged by merely modifying a specific character of a query to upper-case.”