← Vulnerability feed

Vulnerability record · CVE-2021-25037 · published 17 January 2022

CVE-2021-25037: Aioseo all in one seo sql injection vulnerability

Aioseo · All In One Seo

The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to privileged information from the affected site’s database (e.g., usernames and hashed passwords).

6.5 CVSS 3.1 Medium EPSS 1.3% · top 30.9% CWE-89 · SQL injection
6.5CVSS 3.1 base score, v2 4.0
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to privileged information from the affected site’s database (e.g., usernames and hashed passwords).

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-25037 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-38093Aioseo all in one seo cross-site request forgery vulnerabilityMultiple Cross-Site Request Forgery (CSRF) vulnerabilities in All in One SEO plugin <= 4.2.3.1 at WordPress.EPSS 0.40%8.8CVE-2021-25036Aioseo all in one seo improper authentication vulnerabilityThe All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the …EPSS 3.0%8.8CVE-2021-24307All in One SEO WordPress plugin PHP object injection leads to RCEThe All in One SEO WordPress plugin before 4.1.0.2 unserializes values from a user-uploaded backup .ini file in the Tool > Import/Export section. Bec…EPSS 53%analysed6.5CVE-2022-42494Aioseo all in one seo server-side request forgery (ssrf) vulnerabilityServer Side Request Forgery (SSRF) vulnerability in All in One SEO Pro plugin <= 4.2.5.1 on WordPress.EPSS 0.60%6.1CVE-2024-3368Aioseo all in one seo cross-site scripting vulnerabilityThe All in One SEO WordPress plugin before 4.6.1.1 does not validate and escape some of its Post fields before outputting them back, which could allo…EPSS 0.37%5.4CVE-2025-2892Aioseo all in one seo cross-site scripting vulnerabilityThe All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting v…EPSS 0.29%5.4CVE-2024-3554Aioseo all in one seo cross-site scripting vulnerabilityThe All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Si…EPSS 0.45%5.4CVE-2023-0586Aioseo all in one seo cross-site scripting vulnerabilityThe All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2021-25037), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.