Tech-Evangelist

Technical Articles, Musings and Opinions from Tech-Evangelist

  • Home
  • About
  • Guidelines
Previous article: Design Considerations With Responsive Design Websites
Next article: Russian Hackers Have Stolen Over 1.2 Billion Passwords

All In One SEO Pack Vulnerabilities Found

June 3, 2014 By Doogie - Copyright - All Rights Reserved

If you use the WordPress All In One SEO Pack plugin and have not updated it recently, do it right now. Two potentially serious weaknesses have been discovered.

The bad news is these are potentially very serious security holes that could allow a hacker to take control of some aspects of you site or inject cross-site scripting (XSS) attacks on users. The good news is that a security auditing firm found the weaknesses and the author of the All In One SEO Pack plugin has patched the holes in version 2.1.6.

all-in-one-seo-2.1.6Now that the word is out about the exploits, hackers will undoubtedly be looking for ways to take advantage of the problems in unpatched versions of the plugin.

The problems were discovered during a routine security audit performed by Securi>. One big problem with the older versions of the plugin is that the All In One SEO Pack plugin publishes the version number within the web page HTML code, which makes it very easy for hackers to identify unprotected web sites.

The first exploit could allow hackers to change the HTML title tags and meta data on a site, which could be used to trash a websites rankings with search engines.

The second is cross-site scripting, which is typically malicious forms of JavaScript code that extracts information from users, or alters the way a website appears.

All In One SEO Pack and WordPress SEO by Yoast are the two most popular SEO plugins. While the former shows a greater number of downloads, it has also been available much longer. Over the past few years a lot of WordPress users have migrated to Yoast’s plugin because it is more comprehensive with many features not found on All In One SEO. Both have historically been rock solid plugins.

Filed Under: WordPress Tutorials

Categories

  • Affiliate Marketing
  • CSS Tutorials
  • FileZilla Tutorials
  • Home Theater
  • Internet Marketing
  • Internet Technology
  • Kindle Tips
  • MySQL Tutorials
  • Online Auction Tips
  • Paint Shop Pro Tutorials
  • PHP Tutorials
  • Tech News
  • Thunderbird Tutorials
  • Video Production
  • Web Site Development
  • WordPress Tutorials
Content and images are copyrighted by Tech-Evangelist.com and others

Copyright © 2023 Tech-Evangelist.com - All Rights Reserved
Posted code samples are free to use. Do not reproduce or republish articles or content on another web site.

Privacy Policy : Terms of Use