Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Aioseo

First CVE: May 24, 2021Active for: 5 yearsTotal CVEs: 10
24.6
VTI Score
Low

Aioseo develops the All in One SEO WordPress plugin, a widely adopted search-engine optimization tool deployed across numerous WordPress sites. The plugin's vulnerability profile reflects its role as a web-facing application component, with the recurrent weakness classes—cross-site scripting, cross-site request forgery, deserialization flaws, and authentication weaknesses—characteristic of plugin-layer input handling and session management in the WordPress ecosystem. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Aioseo over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 24, 2021
5 years ago
Most Recent CVE
May 19, 2025
431 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-24307HIGH
The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the tim
May 24, 20218.858NONO
CVE-2021-25036HIGH
The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may gran
Jan 17, 20228.829NONO
CVE-2022-38093HIGH
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in All in One SEO plugin <= 4.2.3.1 at WordPress.
Sep 9, 20228.827NONO
CVE-2021-25037MEDIUM
The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and
Jan 17, 20226.523NONO
CVE-2022-42494MEDIUM
Server Side Request Forgery (SSRF) vulnerability in All in One SEO Pro plugin <= 4.2.5.1 on WordPress.
Nov 8, 20226.522NONO
CVE-2023-0586MEDIUM
The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input
Feb 24, 20235.421NONO
CVE-2024-3368MEDIUM
The All in One SEO WordPress plugin before 4.6.1.1 does not validate and escape some of its Post fields before outputting them back, which could allow users with the contributor r
May 20, 20246.120NONO
CVE-2023-0585MEDIUM
The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input
Feb 24, 20234.819NONO
CVE-2025-2892MEDIUM
The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post Meta Description an
May 19, 20255.417NONO
CVE-2024-3554MEDIUM
The All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's s
May 2, 20245.417NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
70%
30%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (40.0%)
Unknown0 (0.0%)
Required6 (60.0%)
Privileges Required
Low6 (60.0%)
High2 (20.0%)
None2 (20.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Aioseo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Aioseo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Aioseo's Products

View all 3 CNAs →

Top CWEs