HomeNewsSecurity & VulnerabilityA vulnerability in the All-in-One SEO Put 3 million websites data at...

A vulnerability in the All-in-One SEO Put 3 million websites data at risk

-

Last Updated on 23/12/2021 by Riya

Marc Montpas, an Automattic security expert discovered two flaws in All in One SEO, a powerful WordPress SEO-optimization tool, that, when coupled into an attack chain, might make website owners vulnerable to site acquisition. Over 3 million sites employ the plugin.

Based on the most recent research at Sucuri, an adversary having an account on the site – including a subscriber, shopping account owner, or member – could leverage the power of the weaknesses, which are a privilege-escalation flaw and a SQL-injection vulnerability.

As per Sucuri, the flaws are ideal for the straightforward attack, thus users should switch to the patched version, v. 4.1.5.3.According to Sucuri experts, the flaw “may be leveraged by merely modifying a specific character of a query to upper-case.”

Riya
Riya
Riya is a technology enthusiast and an avid researcher. She writes about consumer tech, hacking, and technology consumer issues at TheDigitalHacker.
- Advertisment -[the_ad id="13487"]

Must Read