WordPress websites using the popular “All in One SEO Pack” plugin could be downgraded in search engines or infected with malicious code, due to dangerous vulnerabilities that were discovered and patched a few days ago.
The vulnerabilities could allow hackers to conduct attacks against vulnerable websites running versions earlier than 2.1.6. The plugin has been downloaded approximately 19 million times.
Security researcher Marc-Alexandre Montpas revealed the vulnerabilities and urged users to upgrade to the latest version of the plugin.
“If your website has subscribers, authors, and non-admin users logged into wp-admin… or if you have open registration, then you are at risk,” Montpas said.
“In the first case, a logged-in user, without administrator privileges, could add or modify certain parameters used by the plugin, such as the post’s SEO title, description, and keyword meta tags,” the researcher pointed out.
“… We also discovered that this vulnerability can be used in conjunction with another vulnerability to execute malicious Javascript code in the administrator control panel, meaning an attacker could potentially inject JavaScript code to, for example, change the administrator account password or leave a backdoor in your website’s files for future use.”.

