Security breach on All in One SEO Pack

51
3.6K followers
Updated

Many of our websites could be in risk of compromise if we don't update "All in One SEO Pack" plugin. The new version will fix serious vulnerabilities.

Why?!

Well Sucuri researches (This a Web security firm) found two flaws in “All in One SEO Pack”

If your site has subscribers, authors and non-admin users logging in to wp-admin, you are a risk. If you have open registration, you are at risk, so you have to update the plugin now. the Sucuri researchers wrote in a blog.

In other words, The first flaw can be exploited by a regular user (Author or a subscriber) to change your SEO description (in a blog or page) and keywords meta tags, causing decreasing Search Engine Results Page (SERP) if is using maliciously.

The second flaw sucuri explains:

we also discovered this bug can be used with another vulnerability to execute malicious Javascript code on an administrator’s control panel.

This means an attacker could do things like change your admin account’s password or insert backdoor code into your website files to conduct other malicious activities later time as Sucuri researchers said.

Solution?!

Yes. Don't panic. It's very easy just update your "All in One SEO Pack" from Wordpress repository. :D

Hope helps you. :)

Regards

Jorge

Login
Create Your Free Wealthy Affiliate Account Today!
icon
4-Steps to Success Class
icon
One Profit Ready Website
icon
Market Research & Analysis Tools
icon
Millionaire Mentorship
icon
Core “Business Start Up” Training

Recent Comments

69

Thank you Jorge....I haven't reached the need to do this yet...but the importance of updating at once is stored on memory.

Yeah. Right now it's very important. Hope helps. :)

Wow. Didn't know this could happen. And there are sometimes these weird email addresses coming up as new registered users of my site.

Stephon ,

You can choose to people don't register to your website. :)

Yeah and I didn't know when I saw that blog from Sucuri. :(

I always update plugins as soon as the updates are available. Updates usually contain fixes and improvements, so it's worth doing this as a matter of habit. Thanks for letting us know, Jorge, as some people delay updating and this is an important one. ~Jude

Excellent habit Jude! Yeah it's very necessary to updates our plugins and now we know some reasons why. :)

Thanks Jorge, doing that right now!!

Phew! Now you are safe. :D

Thanks for reading, :)

This is something I didn't realize and appreciate this info.

Tommy,

When I saw that blog from sucri I didn't realize too. That's why I created this blog. Thanks for reading., :)

Defiantly worth knowing, thanks for the heads up Jorge

Yes . It's important to know. Most welcome. :)

Thanks for the reminder. High priority!!

Ade,

Yeah please add on your priority list. Very important. Thanks for reading. :)

I did the update. Thanks Jorge!

Fantastic. :D

Thanks!

No probs. Did you update your SEO plugin?!

Yesterday. Appreciate it!

Aw fab. :)

Thanks for the heads up Jorge. I will update mine

Yeah. Do it now because it's very important of you have another wp users.

Most welcome. :D

Thank you for the heads up. I updated most of mine today. ;)

Most welcome Kary. I always try to have my domains safe. :)

See more comments

Login
Create Your Free Wealthy Affiliate Account Today!
icon
4-Steps to Success Class
icon
One Profit Ready Website
icon
Market Research & Analysis Tools
icon
Millionaire Mentorship
icon
Core “Business Start Up” Training