6.5
CVSSv2

CVE-2021-25036

Published: 17/01/2022 Updated: 07/11/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The All in One SEO WordPress plugin prior to 4.1.5.3 is affected by a Privilege Escalation issue, which exists during an internal audit by the Jetpack Scan team, and may grant bad actors access to protected REST API endpoints they shouldn’t have access to. This could ultimately enable users with low-privileged accounts, like subscribers, to perform remote code execution on affected sites.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

aioseo all in one seo