← Vulnerability feed

Vulnerability record · CVE-2024-3368 · published 20 May 2024

CVE-2024-3368: Aioseo all in one seo cross-site scripting vulnerability

Aioseo · All In One Seo

The All in One SEO WordPress plugin before 4.6.1.1 does not validate and escape some of its Post fields before outputting them back, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

6.1 CVSS 3.1 Medium EPSS 0.37% · top 71.8% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
0.37%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The All in One SEO WordPress plugin before 4.6.1.1 does not validate and escape some of its Post fields before outputting them back, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-3368 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-38093Aioseo all in one seo cross-site request forgery vulnerabilityMultiple Cross-Site Request Forgery (CSRF) vulnerabilities in All in One SEO plugin <= 4.2.3.1 at WordPress.EPSS 0.40%8.8CVE-2021-25036Aioseo all in one seo improper authentication vulnerabilityThe All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the …EPSS 3.0%8.8CVE-2021-24307All in One SEO WordPress plugin PHP object injection leads to RCEThe All in One SEO WordPress plugin before 4.1.0.2 unserializes values from a user-uploaded backup .ini file in the Tool > Import/Export section. Bec…EPSS 53%analysed6.5CVE-2022-42494Aioseo all in one seo server-side request forgery (ssrf) vulnerabilityServer Side Request Forgery (SSRF) vulnerability in All in One SEO Pro plugin <= 4.2.5.1 on WordPress.EPSS 0.60%6.5CVE-2021-25037Aioseo all in one seo sql injection vulnerabilityThe All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit…EPSS 1.3%5.4CVE-2025-2892Aioseo all in one seo cross-site scripting vulnerabilityThe All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting v…EPSS 0.29%5.4CVE-2024-3554Aioseo all in one seo cross-site scripting vulnerabilityThe All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Si…EPSS 0.45%5.4CVE-2023-0586Aioseo all in one seo cross-site scripting vulnerabilityThe All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2024-3368), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.