Impact
A defect in Syed Balkhi’s All In One SEO Pack plugin permits insertion of sensitive information into data that is transmitted, allowing an attacker to retrieve embedded sensitive data. This flaw falls under CWE‑201 – Information Exposure Through an Insecure Implementation. The result is unauthorized disclosure of confidential information, posing a risk to confidentiality of user data stored or processed by the website.
Affected Systems
WordPress installations that run Syed Balkhi’s All In One SEO Pack plugin, version 4.8.7.1 or earlier, are impacted. Site administrators hosting the plugin should be aware of this exposure.
Risk and Exploitability
The CVSS score of 4.3 places the vulnerability in the moderate range, while the EPSS value of less than 1 % indicates a low probability of exploitation at this time. The issue is not listed in the CISA KEV catalog. Though the description does not detail an explicit attack vector, it is reasonable to assume that the flaw could be leveraged through web requests to the plugin’s exposed endpoint or via crafted input that triggers data leakage. In the absence of a high‑severity score and low exploitation likelihood, the primary concern remains the potential for sensitive data exposure rather than active compromise.
OpenCVE Enrichment
EUVD