What the vulnerability does
01Description
Server Side Request Forgery (SSRF) vulnerability in All in One SEO Pro plugin <= 4.2.5.1 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
What the vulnerability does
Server Side Request Forgery (SSRF) vulnerability in All in One SEO Pro plugin <= 4.2.5.1 on WordPress.
Explanation of Vulnerability in Simple Terms
All in One SEO Pro versions up to 4.2.5.1 contain a server-side request forgery vulnerability. An authenticated administrator can craft requests that cause the plugin to make HTTP calls to internal or external systems on the attacker's behalf. The vulnerability requires high-level admin access and network connectivity but can expose internal services or leak sensitive data.
What an attacker can do
Make the site send HTTP requests to internal or external systems to probe or interact with them.
Potential impact on your site
A compromised admin account could be used to scan your internal network, access internal services, or exfiltrate data via the plugin.
Conditions required to exploit
Administrator account access; attacker must be logged in with admin privileges.
Key dates
External resources
Related vulnerabilities