← Vulnerability feed

Vulnerability record · CVE-2021-24307 · published 24 May 2021

CVE-2021-24307: All in One SEO WordPress plugin PHP object injection leads to RCE

Aioseo · All In One Seo

The All in One SEO WordPress plugin before 4.1.0.2 unserializes values from a user-uploaded backup .ini file in the Tool > Import/Export section. Because the plugin bundles the Monolog library, an attacker who can supply a crafted .ini can build a gadget chain and execute arbitrary system commands on the host. The flaw requires an authenticated account holding the aioseo_tools_settings privilege, which is usually an administrator.

8.8 CVSS 3.1 High EPSS 53% · top 1.0% CWE-502 · Deserialization of untrusted data
8.8CVSS 3.1 base score, v2 9.0
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the time admin) to execute arbitrary code on the underlying host. Users can restore plugin's configuration by uploading a backup .ini file in the section "Tool > Import/Export". However, the plugin attempts to unserialize values of the .ini file. Moreover, the plugin embeds Monolog library which can be used to craft a gadget chain and thus trigger system command execution.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityRemote authenticated code execution with high EPSS and a public exploit reference, though it requires a privileged account rather than being unauthenticated.

What it is

The All in One SEO WordPress plugin before 4.1.0.2 unserializes values from a user-uploaded backup .ini file in the Tool > Import/Export section. Because the plugin bundles the Monolog library, an attacker who can supply a crafted .ini can build a gadget chain and execute arbitrary system commands on the host. The flaw requires an authenticated account holding the aioseo_tools_settings privilege, which is usually an administrator.

Impact

An attacker with the required privilege gains arbitrary code execution on the underlying host, leading to full compromise of the WordPress site and potentially the server.

Attack surface

Reached over the network through the plugin's Tool > Import/Export backup restore function, which accepts an uploaded .ini file. Authentication is required with the aioseo_tools_settings privilege; no user interaction beyond the upload is needed.

Exploitation

Not listed in CISA KEV, but EPSS is high at roughly 0.53 (99th percentile) and a WPScan reference is tagged Exploit, indicating public exploit detail exists. No ransomware usage is documented.

What to do

  • Update the All in One SEO plugin to 4.1.0.2 or later immediately.
  • Restrict the aioseo_tools_settings capability to the smallest possible set of trusted accounts.
  • Audit administrator accounts and remove or downgrade unused privileged users.
  • Block or monitor uploads of .ini files to the plugin's import/export endpoint at the WAF or reverse proxy.
  • If patching is delayed, disable the plugin's Tool > Import/Export feature where possible.

Detection

  • Monitor web server and plugin logs for POST requests to the All in One SEO import/export endpoint with .ini file uploads.
  • Alert on unexpected child processes spawned by the web server or PHP-FPM (for example shell, curl, wget).
  • Search for newly created or modified PHP files in the WordPress uploads and plugin directories.
  • Review administrator and aioseo_tools_settings role changes for unauthorized additions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-24307 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-38093Aioseo all in one seo cross-site request forgery vulnerabilityMultiple Cross-Site Request Forgery (CSRF) vulnerabilities in All in One SEO plugin <= 4.2.3.1 at WordPress.EPSS 0.40%8.8CVE-2021-25036Aioseo all in one seo improper authentication vulnerabilityThe All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the …EPSS 3.0%6.5CVE-2022-42494Aioseo all in one seo server-side request forgery (ssrf) vulnerabilityServer Side Request Forgery (SSRF) vulnerability in All in One SEO Pro plugin <= 4.2.5.1 on WordPress.EPSS 0.60%6.5CVE-2021-25037Aioseo all in one seo sql injection vulnerabilityThe All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit…EPSS 1.3%6.1CVE-2024-3368Aioseo all in one seo cross-site scripting vulnerabilityThe All in One SEO WordPress plugin before 4.6.1.1 does not validate and escape some of its Post fields before outputting them back, which could allo…EPSS 0.37%5.4CVE-2025-2892Aioseo all in one seo cross-site scripting vulnerabilityThe All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting v…EPSS 0.29%5.4CVE-2024-3554Aioseo all in one seo cross-site scripting vulnerabilityThe All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Si…EPSS 0.45%5.4CVE-2023-0586Aioseo all in one seo cross-site scripting vulnerabilityThe All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2021-24307), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.