Vulnerabilities discovered in popular WordPress plugin

Share this article:

Users of the All in One SEO Pack are being told to update to the latest version of the popular WordPress plugin because researchers with web monitoring and malware clean up service Sucuri uncovered two vulnerabilities last week during an audit of the code.

A privilege escalation flaw could enable a user without administrative privileges – such as an author or subscriber – to make modifications, including to SEO title, description and keyword meta tags, according to a Saturday post by Marc-Alexandre Montpas, an analyst with Sucuri.

The privilege escalation bug could be used with a second flaw that enables execution of malicious Javascript code on an administrator's control panel, meaning attackers could change administrator account passwords and even open some backdoors for easier access in the future, according to the post.

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

TOP COMMENTS

More in News

Information sharing requires breaking down barriers, White House cyber guru says

Information sharing requires breaking down barriers, White House ...

The White House has advanced an agenda to promote and facilitate information sharing on security threats and vulnerabilities.

Worm variant of Android ransomware, Koler, spreads via SMS

Worm variant of Android ransomware, Koler, spreads via ...

Upon infection, the Koler variant will send an SMS message to all contacts in the device's address book.

Patch for Windows flaw can be bypassed, prompts temporary fix from Microsoft

Patch for Windows flaw can be bypassed, prompts ...

The Windows zero-day received a patch last week, but the fix can still be bypassed by crafty attackers.