HomeNewsSecurity & VulnerabilityA vulnerability in the All-in-One SEO Put 3 million websites data at...

A vulnerability in the All-in-One SEO Put 3 million websites data at risk

-

Last Updated on 23/12/2021 by Riya

Marc Montpas, an Automattic security expert discovered two flaws in All in One SEO, a powerful WordPress SEO-optimization tool, that, when coupled into an attack chain, might make website owners vulnerable to site acquisition. Over 3 million sites employ the plugin.

Based on the most recent research at Sucuri, an adversary having an account on the site – including a subscriber, shopping account owner, or member – could leverage the power of the weaknesses, which are a privilege-escalation flaw and a SQL-injection vulnerability.

As per Sucuri, the flaws are ideal for the straightforward attack, thus users should switch to the patched version, v. 4.1.5.3.According to Sucuri experts, the flaw “may be leveraged by merely modifying a specific character of a query to upper-case.”

Riya
Riya
Riya is a technology enthusiast and an avid researcher. She writes about consumer tech, hacking, and technology consumer issues at TheDigitalHacker.
- Advertisment -

Must Read

edge-ai

Challenges and Opportunities in Deploying AI Solutions in Edge Computing Environments

0
Edge AI is a ground-breaking new paradigm that has the potential to completely change how companies run. Organizations can seize new chances for creativity,...