Security breach on All in One SEO Pack
Many of our websites could be in risk of compromise if we don't update "All in One SEO Pack" plugin. The new version will fix serious vulnerabilities.
Well Sucuri researches (This a Web security firm) found two flaws in “All in One SEO Pack”
If your site has subscribers, authors and non-admin users logging in to wp-admin, you are a risk. If you have open registration, you are at risk, so you have to update the plugin now. the Sucuri researchers wrote in a blog.
In other words, The first flaw can be exploited by a regular user (Author or a subscriber) to change your SEO description (in a blog or page) and keywords meta tags, causing decreasing Search Engine Results Page (SERP) if is using maliciously.
The second flaw sucuri explains:
This means an attacker could do things like change your admin account’s password or insert backdoor code into your website files to conduct other malicious activities later time as Sucuri researchers said.
Yes. Don't panic. It's very easy just update your "All in One SEO Pack" from Wordpress repository. :D
Hope helps you. :)
See more comments