Impact
The All In One SEO Pack plugin has a missing authorization mechanism that enables an attacker to bypass normal access controls and perform privileged actions on the WordPress site. This flaw could let the attacker alter or inspect SEO settings, potentially gaining further insight into the site’s configuration or facilitating additional attacks. The weakness originates from inadequate authentication checks and is classified as CWE‑862.
Affected Systems
Syed Balkhi All In One SEO Pack plugins that are at or below version 4.8.7.1 are affected. The issue reports impact on WordPress installations that rely on this plugin, regardless of the core WordPress version. No specific WordPress core version is identified as required for exploitation.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk, while the EPSS score of less than 1% signifies a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not become a widely used weapon. Inferred from the description, the attack vector is remote via HTTP requests to the plugin's administrative endpoints. An attacker would first need access to the site’s administrative section or a user role that can reach the plugin configuration pages. The flaw can be leveraged to modify or read sensitive SEO data, and potentially provides a foothrough for additional exploitation if combined with other local vulnerabilities.
OpenCVE Enrichment
EUVD