Aioseo develops the All in One SEO WordPress plugin, a widely adopted search-engine optimization tool deployed across numerous WordPress sites. The plugin's vulnerability profile reflects its role as a web-facing application component, with the recurrent weakness classes—cross-site scripting, cross-site request forgery, deserialization flaws, and authentication weaknesses—characteristic of plugin-layer input handling and session management in the WordPress ecosystem. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aioseo over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24307HIGH The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the tim | May 24, 2021 | 8.8 | 58 | NO | NO |
CVE-2021-25036HIGH The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may gran | Jan 17, 2022 | 8.8 | 29 | NO | NO |
CVE-2022-38093HIGH Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in All in One SEO plugin <= 4.2.3.1 at WordPress. | Sep 9, 2022 | 8.8 | 27 | NO | NO |
CVE-2021-25037MEDIUM The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and | Jan 17, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-42494MEDIUM Server Side Request Forgery (SSRF) vulnerability in All in One SEO Pro plugin <= 4.2.5.1 on WordPress. | Nov 8, 2022 | 6.5 | 22 | NO | NO |
CVE-2023-0586MEDIUM The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input | Feb 24, 2023 | 5.4 | 21 | NO | NO |
CVE-2024-3368MEDIUM The All in One SEO WordPress plugin before 4.6.1.1 does not validate and escape some of its Post fields before outputting them back, which could allow users with the contributor r | May 20, 2024 | 6.1 | 20 | NO | NO |
CVE-2023-0585MEDIUM The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input | Feb 24, 2023 | 4.8 | 19 | NO | NO |
CVE-2025-2892MEDIUM The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post Meta Description an | May 19, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-3554MEDIUM The All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's s | May 2, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aioseo.
Media articles that mention a CVE ID that affects a product developed by Aioseo — matched by CVE ID, not by vendor name.