Security breach on All in One SEO Pack
Many of our websites could be in risk of compromise if we don't update "All in One SEO Pack" plugin. The new version will fix serious vulnerabilities.
Why?!
Well Sucuri researches (This a Web security firm) found two flaws in “All in One SEO Pack”
If your site has subscribers, authors and non-admin users logging in to wp-admin, you are a risk. If you have open registration, you are at risk, so you have to update the plugin now. the Sucuri researchers wrote in a blog.
In other words, The first flaw can be exploited by a regular user (Author or a subscriber) to change your SEO description (in a blog or page) and keywords meta tags, causing decreasing Search Engine Results Page (SERP) if is using maliciously.
The second flaw sucuri explains:
we also discovered this bug can be used with another vulnerability to execute malicious Javascript code on an administrator’s control panel.
This means an attacker could do things like change your admin account’s password or insert backdoor code into your website files to conduct other malicious activities later time as Sucuri researchers said.
Solution?!
Yes. Don't panic. It's very easy just update your "All in One SEO Pack" from Wordpress repository. :D
Hope helps you. :)
Regards
Jorge
Recent Comments
69
I always update plugins as soon as the updates are available. Updates usually contain fixes and improvements, so it's worth doing this as a matter of habit. Thanks for letting us know, Jorge, as some people delay updating and this is an important one. ~Jude
Excellent habit Jude! Yeah it's very necessary to updates our plugins and now we know some reasons why. :)
See more comments
Thank you Jorge....I haven't reached the need to do this yet...but the importance of updating at once is stored on memory.
Yeah. Right now it's very important. Hope helps. :)