1 min read

Update Your All In One SEO Plugin For Security Patch

Do you own and operate a WordPress website?  Do you also use the “All in One” SEO plugin?

If you answered yes to both of those questions, then be aware that you’ll want to update that plugin as soon as possible.

Recently security researcher Marc Montpas from Automattic Security discovered and reported a pair of critical security flaws.

These flaws put any website using the non-upgraded version of that plugin at risk. The security flaws are being tracked as CVE-2021-25036 and CVE-2021-25037 respectively. The first is an Authenticated Privilege Escalation bug and the second an Authenticated SQL Injection bug.

The bad news is that there are currently more than 800,000 websites running the outdated and vulnerable version of the plugin.  The good news is that the development team behind the All-in-One plugin responded very quickly and delivered an update to their product on December 7th of this year (2021) which addresses both issues.

The reason these flaws are so dangerous lies in the fact that all an attacker needs to be able to successfully execute an attack that leverages them is an authenticated account. That is generally a relatively easy thing to get.  It doesn’t have to have a lot of rights or privileges so a low-level permission group like “Subscriber” is sufficient.

Using that as a starting point it would be easy for an attacker to escalate his or her own privileges and cause all sorts of damage to the site itself or exfiltrate data from it.  Not good.

Now is the Time to Update Your All-in-One SEO Plugin

In any case there’s a simple solution ready and waiting.  Just check to see what version of the All-in-One plugin you’re using. If you don’t already have it download and install the 4.1.5.3 patch.  Stay safe out there.  There may yet be a few additional surprises in store for us in what remains of the year.

Used with permission from Article Aggregator

Your AI Is Everywhere. Your Compliance Docs Shouldn't Be.

Your AI Is Everywhere. Your Compliance Docs Shouldn't Be.

AI didn’t roll out in one clean, controlled launch. It crept in…in different ways, in multiple places, at different times. Kind of like weeds in a...

Read the full blog
Mapping AI Decision Pipelines Into Documented Compliance Workflows

Mapping AI Decision Pipelines Into Documented Compliance Workflows

You know how kids like to ask “Why?" and "How come?” Questions like, “Why is water wet? How come you write with your left hand?” There are actually...

Read the full blog
IT Support Response Time in Portland: What SLAs Should You Expect?

IT Support Response Time in Portland: What SLAs Should You Expect?

Key Takeaways Response time is only part of the equation, resolution time is what truly impacts your business Portland businesses should expect...

Read the full blog

1 min read

Update Apple Devices Soon for Important Security Patch

Apple released a very important security update today. The update fixes a pair of zero-day vulnerabilities that have been spotted in use in the wild...

Read the full blog

1 min read

FTC Enforcing That Businesses Patch Log4j Java Security Issue

By now you’re almost certainly aware of the Log4j Java issue.

Read the full blog

1 min read

Beware Certain Sites Because Of TSA PreCheck Renewal Scam

According to a report recently released by Abnormal Security there’s been a huge upsurge of instances of people getting scammed after visiting what...

Read the full blog