Vulnerability record · CVE-2021-24307 · published 24 May 2021
CVE-2021-24307: All in One SEO WordPress plugin PHP object injection leads to RCE
Aioseo · All In One Seo
The All in One SEO WordPress plugin before 4.1.0.2 unserializes values from a user-uploaded backup .ini file in the Tool > Import/Export section. Because the plugin bundles the Monolog library, an attacker who can supply a crafted .ini can build a gadget chain and execute arbitrary system commands on the host. The flaw requires an authenticated account holding the aioseo_tools_settings privilege, which is usually an administrator.
Description
The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the time admin) to execute arbitrary code on the underlying host. Users can restore plugin's configuration by uploading a backup .ini file in the section "Tool > Import/Export". However, the plugin attempts to unserialize values of the .ini file. Moreover, the plugin embeds Monolog library which can be used to craft a gadget chain and thus trigger system command execution.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote authenticated code execution with high EPSS and a public exploit reference, though it requires a privileged account rather than being unauthenticated.
What it is
The All in One SEO WordPress plugin before 4.1.0.2 unserializes values from a user-uploaded backup .ini file in the Tool > Import/Export section. Because the plugin bundles the Monolog library, an attacker who can supply a crafted .ini can build a gadget chain and execute arbitrary system commands on the host. The flaw requires an authenticated account holding the aioseo_tools_settings privilege, which is usually an administrator.
Impact
An attacker with the required privilege gains arbitrary code execution on the underlying host, leading to full compromise of the WordPress site and potentially the server.
Attack surface
Reached over the network through the plugin's Tool > Import/Export backup restore function, which accepts an uploaded .ini file. Authentication is required with the aioseo_tools_settings privilege; no user interaction beyond the upload is needed.
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 0.53 (99th percentile) and a WPScan reference is tagged Exploit, indicating public exploit detail exists. No ransomware usage is documented.
What to do
- Update the All in One SEO plugin to 4.1.0.2 or later immediately.
- Restrict the aioseo_tools_settings capability to the smallest possible set of trusted accounts.
- Audit administrator accounts and remove or downgrade unused privileged users.
- Block or monitor uploads of .ini files to the plugin's import/export endpoint at the WAF or reverse proxy.
- If patching is delayed, disable the plugin's Tool > Import/Export feature where possible.
Detection
- Monitor web server and plugin logs for POST requests to the All in One SEO import/export endpoint with .ini file uploads.
- Alert on unexpected child processes spawned by the web server or PHP-FPM (for example shell, curl, wget).
- Search for newly created or modified PHP files in the WordPress uploads and plugin directories.
- Review administrator and aioseo_tools_settings role changes for unauthorized additions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://aioseo.com/changelog/ | Release NotesVendor Advisory |
| https://wpscan.com/vulnerability/ab2c94d2-f6c4-418b-bd14-711ed164bcf1 | ExploitThird Party Advisory |
| https://aioseo.com/changelog/ | Release NotesVendor Advisory |
| https://wpscan.com/vulnerability/ab2c94d2-f6c4-418b-bd14-711ed164bcf1 | ExploitThird Party Advisory |
Track CVE-2021-24307 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-24307), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.