CERT-In Vulnerability Note
CIVN-2021-0376
Multiple vulnerabilities in All in One SEO Wordpress Plugin
Original Issue Date:December 29, 2021
Severity Rating: HIGH
Software Affected
- All In One SEO Wordpress Plugin versions between 4.0.0 and 4.1.5.2 inclusively.
Overview
Multiple vulnerabilities have been reported in All In One SEO Wordpress Plugin which could allow an attacker to gain elevated privileges and perform SQL injection on the targeted system.
Description
1. Privilege Escalation Vulnerability
(
CVE-2021-25036
)
This vulnerability exists in All In One SEO Wordpress Plugin due to access of every single endpoint plugin registers by low-privileged users in REST API. An attacker could exploit this vulnerability by changing the case-insensitive strings. Successful exploitation of this vulnerability could allow an attacker to gain elevated privileges and execute arbitrary code on the targeted system.
2. SQL Injection Vulnerability
(
CVE-2021-25037
)
This vulnerability exists in All In One SEO Wordpress Plugin due to improper input validation in REST API. An attacker could exploit this vulnerability by appending specially crafted user input to an SQL query. Successful exploitation of this vulnerability could allow an attacker to inject a SQL query to obtain sensitive information on the targeted system.
Solution
Apply appropriate upgrade as mentioned:
https://wordpress.org/plugins/all-in-one-seo-pack/
Vendor Information
Wordpress
https://wordpress.org/plugins/all-in-one-seo-pack/
References
Jetpack
https://jetpack.com/2021/12/14/severe-vulnerabilities-fixed-in-all-in-one-seo-plugin-version-4-1-5-3/
Bleeping Computer
https://www.bleepingcomputer.com/news/security/800k-wordpress-sites-still-impacted-by-critical-seo-plugin-flaw/
CVE Name
CVE-2021-25036
CVE-2021-25037
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|