Topics Tools Books & Guides Talk to Securafy

Knowledge Hub / IT Operations

IT Operations

Update Your All In One SEO Plugin For Security Patch

Update Your All In One SEO Plugin For Security Patch

Randy Hall By Randy Hall Updated Jul 2024 2 min read Share

Do you own and operate a WordPress website?  Do you also use the "All in One" SEO plugin?

If you answered yes to both of those questions, then be aware that you'll want to update that plugin as soon as possible.

Recently security researcher Marc Montpas from Automattic Security discovered and reported a pair of critical security flaws.

These flaws put any website using the non-upgraded version of that plugin at risk. The security flaws are being tracked as CVE-2021-25036 and CVE-2021-25037 respectively. The first is an Authenticated Privilege Escalation bug and the second an Authenticated SQL Injection bug.

The bad news is that there are currently more than 800,000 websites running the outdated and vulnerable version of the plugin.  The good news is that the development team behind the All-in-One plugin responded very quickly and delivered an update to their product on December 7th of this year (2021) which addresses both issues.

The reason these flaws are so dangerous lies in the fact that all an attacker needs to be able to successfully execute an attack that leverages them is an authenticated account. That is generally a relatively easy thing to get.  It doesn't have to have a lot of rights or privileges so a low-level permission group like "Subscriber" is sufficient.

Using that as a starting point it would be easy for an attacker to escalate his or her own privileges and cause all sorts of damage to the site itself or exfiltrate data from it.  Not good.

In any case there's a simple solution ready and waiting.  Just check to see what version of the All-in-One plugin you're using. If you don't already have it download and install the 4.1.5.3 patch.  Stay safe out there.  There may yet be a few additional surprises in store for us in what remains of the year.

Join The Conversation

Have a question or perspective on this topic? Add it below.

Randy Hall

About The Author

Randy Hall · CEO & Founder

Randy Hall is the CEO and Founder of Securafy, with decades of experience helping organizations make smarter, safer decisions about technology.

A frequent speaker and instructor at national IT events, Randy has advised thousands of organizations, from startups and SMBs to large enterprises and U.S. government entities, on secure, practical technology adoption. He writes about the decisions business leaders are often expected to make without enough context, including cybersecurity, compliance, AI, cyber insurance, IT strategy, and business resilience.

Outside the office, you’ll often find Randy on Lake Erie enjoying time on his 38-foot Chris-Craft.

Writes about: Cybersecurity strategy, compliance, AI security, business resilience, cyber insurance, SMB risk, IT leadership

More From This Author →

Get Practical Cybersecurity Field Notes

Monthly cybersecurity, compliance, and IT strategy updates from Securafy, written for business owners who need clear next steps.

  • Practical security tips from our Cyber Security Drip series
  • The Securafy Times, our monthly roundup on compliance and IT strategy
  • Occasional updates on new tools, guides, and research
  • No spam — unsubscribe anytime