All in One SEO
cpe:2.3:a:semperfiwebdesign:all_in_one_seo_pack:*:*:*:*:wordpress:*:*, +1 more
- <= 4.9.7
A vulnerability allowing sensitive information exposure has been identified in the All in One SEO plugin for WordPress, affecting versions through 4.9.7. The issue arises from internal option data being sent to wp_localize_script() in post editor contexts, without proper masking for users with low privileges. This flaw enables authenticated attackers with contributor-level access and above to access API/OAuth tokens and license-related information from the page source.
Exploitation of this vulnerability allows authenticated users with contributor-level access and above to view sensitive internal option data, including API/OAuth tokens and license-related values, through the page source.
Users are advised to update the All in One SEO plugin to version 4.9.7.1 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.