Older versions of the All in One SEO Pack WordPress plugin contain a vulnerability that allows an attacker to store malicious code in the website's admin that could potentially help them gain control of it.
Currently, if one goes to Popular in the WordPress Plugin tab, the first plugin listed above all others is Semper Fi Web Design's All in One SEO Pack.
The plugin helps webmasters improve the SEO (Search Engine Optimization) features of their website through an easy-to-use panel with on/off settings.
One of these settings is called Bot Blocker and allows users to decide which search engine crawlers to block so they cannot access their site. This setting is disabled (off) by default, so there is no reason for plugin users to worry.
Where webmasters have turned this feature On, they are probably aware that there is a log that records all bots that have been rejected and the time they visit their websites.
According to security researcher David Vaartjes, the plugin records these visits without sanitizing the text included in the User Agent strings and Referrer header sections.
All an attacker has to do is change one of these two attributes by adding malicious code to the end, for a bot that knows it is blocked from the site.
This (malicious) code is stored in the WordPress website's database and is automatically executed when the administrator visits the logpage.
Adding JavaScript code that steals admin cookies is very simple for any low to moderate level attacker. Cookies can be used to hijack admin logins or perform other CSRF attacks.
Webmasters using this plugin should be aware that this issue has been fixed in a more recent version of the plugin, which is currently 2.3.7. This attack was only tested on version 2.3.6.1 of All in One SEO Pack, which does not exclude that older versions may also be vulnerable. In this case, updating to the latest version is recommended!


