The WordPress service is one of the most popular and widespread for creating and managing websites. On this platform it is possible to use numerous plugins, one of them being the one that now poses a security problem: All In One SEO.
This plugin is being used by some 3 millions of websites to improve search engine ranking and presents two critical vulnerabilities, resolved in an update released last 7 in December.
This update is not being applied with the necessary speed by website administrators. The attacker could use the vulnerable plugin to bypass the required privilege checks.
El consejo para los administradores web es actualizar el complemento All in One SEO a la versión 4.1.5.3, además de mantener actualizados el resto de plugins para evitar posibles riesgos de seguridad.
Fountain: Engadget
Image: Pixabay
