CVE-2021-24307
HIGHAioseo All IN One Seo < 4.1.0.2 - Insecure Deserialization
Title source: ruleDescription
The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the time admin) to execute arbitrary code on the underlying host. Users can restore plugin's configuration by uploading a backup .ini file in the section "Tool > Import/Export". However, the plugin attempts to unserialize values of the .ini file. Moreover, the plugin embeds Monolog library which can be used to craft a gadget chain and thus trigger system command execution.
Exploits (1)
Scores
CVSS v3
8.8
EPSS
0.4178
EPSS Percentile
97.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
aioseo/all_in_one_seo
< 4.1.0.2
Timeline
Published
May 24, 2021
Tracked Since
Feb 18, 2026