QID 150658
Date Published: 2023-03-15
QID 150658: WordPress All in One SEO Pack Plugin: Multiple Stored Cross-Site Scripting Vulnerabilities (CVE-2023-0585,CVE-2023-0586)
All in One SEO (AIOSEO) is a WordPress plugin that helps website owners optimize their WordPress websites for search engines and social media.
All in One SEO pack contains multiple vulnerabilities:
CVE-2023-0585: The vulnerability is due to insufficient input sanitization and output escaping, which allows authenticated attackers with Administrator or higher privileges to execute arbitrary web scripts. This attack is known as Stored Cross-Site Scripting and it allows the attacker to inject malicious scripts that will execute whenever a user accesses a page that has been injected.
CVE-2023-0586: The vulnerability is related to Stored Cross-Site Scripting, and it can be exploited through multiple parameters due to the insufficient sanitization of input and the lack of proper output escaping. This vulnerability allows authenticated attackers with Contributor+ role or higher privileges to inject malicious web scripts into pages.
Affected Versions:
All in One SEO (AIOSEO) versions up to and including 4.2.9
QID Detection Logic:
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.
Successful exploitation could allow an attacker to execute arbitrary JavaScript code in the context of the interface or allow the attacker to access sensitive, browser-based information.
CVEs related to QID 150658
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| AIOSEO |
|