CVE-2021-24307 is a critical arbitrary code execution vulnerability affecting the All in One SEO WordPress plugin versions prior to 4.1.0.2. Authenticated users with "aioseo_tools_settings" privileges (typically administrators) can exploit this by uploading a malicious .ini backup file, which the plugin attempts to unserialize. This flaw, combined with the embedded Monolog library, allows for the creation of a gadget chain to execute arbitrary system commands on the host. The vulnerability carries a high CVSS score of 8.8, indicating a network-based attack with low complexity and high impact on confidentiality, integrity, and availability. Despite its severity and high FAUCET Risk Score of 97/100, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.1.0.2CPE matchmatch criteria | cpe:2.3:a:aioseo:all_in_one_seo:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.