← WordPress Vulnerabilities
WordPress security by component

All In One SEO Pack

All In One SEO Pack is a WordPress component with 12 published CVE records in this archive. The latest tracked vulnerability was published Dec 18, 2025; the highest CVE/CNA score is 8.5.

Plugin slug: all-in-one-seo-pack

CVE-2025-64295: All In One SEO Pack: A security weakness

All In One SEO Pack is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedDec 18, 2025
Safe version guidanceSee mitigation notes
Safe version
Dec 18, 2025 CVE-2025-64295
All In One SEO Pack: A security weakness
All In One SEO Pack is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Dec 16, 2025 CVE-2025-67950
All In One SEO Pack: SQL injection
All In One SEO Pack is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVDPending
Nov 15, 2025 CVE-2025-12847
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic: A security weakness
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Sep 22, 2025 CVE-2025-58650
All In One SEO Pack: A security weakness
All In One SEO Pack is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Sep 22, 2025 CVE-2025-58649
All In One SEO Pack: A security weakness
All In One SEO Pack is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Feb 24, 2023 CVE-2023-0586
All in One SEO Pack: Cross-site scripting
All in One SEO Pack is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Feb 24, 2023 CVE-2023-0585
All in One SEO Pack: Cross-site scripting
All in One SEO Pack is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Sep 09, 2022 CVE-2022-38093
All In One Seo Pack: Cross-site request forgery
All In One Seo Pack is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Jan 01, 2021 CVE-2020-35946
All In One Seo Pack: Cross-site scripting
All In One Seo Pack is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Feb 11, 2020 CVE-2013-5988
All In One Seo Pack: Cross-site scripting
All In One Seo Pack is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 16, 2019 CVE-2019-16520
All In One Seo Pack: Cross-site scripting
All In One Seo Pack is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Apr 03, 2015 CVE-2015-0902
All In One Seo Pack: A security weakness
All In One Seo Pack is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.0
NVD5.0