WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)

AIOSEO is the WordPress SEO plugin. Boost SEO rankings with AI SEO tools, schema, meta descriptions, XML sitemaps & rank tracking.

24Reported vulnerabilities
8.8Highest CVSS score
5.0.0.1Latest version
3,000,000+Active installs

What to do now

Update All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) to 4.9.9 or later. 24 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 3, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2021-25036 High 8.8 3.0% Before 4.1.5.3 4.1.5.3 January 17, 2022
CVE-2021-25037 Medium 6.5 1.3% Before 4.1.5.3 4.1.5.3 January 17, 2022
CVE-2013-5988 Medium 6.1 1.1% 1.3.6.4 to 1.6.15.2 (inclusive)
2.0 up to (but not including) 2.0.3.1
2.0.3.1 February 11, 2020
CVE-2019-16520 Medium 5.4 1.5% Before 3.2.7 3.2.7 October 16, 2019
CVE-2020-35946 Medium 5.4 0.8% Before 3.6.2 3.6.2 January 1, 2021
CVE-2022-38093 High 8.8 0.4% 4.2.3.1 and earlier 4.2.4 September 9, 2022
WF-c490e344-66da-4176-bd93-7e07a491bfa9 High 7.2 Before 2.3.8 2.3.8 July 13, 2016
WF-4f018e22-bf07-4371-afc1-3e664ea1c5a3 High 7.2 Before 2.3.7 2.3.7 July 1, 2016
CVE-2025-67950 Medium 6.5 0.3% 4.9.1 and earlier 4.9.1.1 December 6, 2025
CVE-2023-0586 Medium 5.4 2.5% 4.2.9 and earlier 4.3.0 February 24, 2023
WF-6a0c948b-7f14-450e-858a-77c1d3dd0761 Medium 6.4 Before 2.10 2.10 October 18, 2018
WF-55a942b7-5d3e-4ddf-8bc3-61ff90a7fdbd Medium 6.3 2.1.5 and earlier 2.1.6 May 31, 2014
WF-60e4c186-5239-464d-be83-1b873f821b3e Medium 6.4 2.1.5 and earlier 2.1.6 May 31, 2014
WF-03ddef11-04cb-4639-afb0-f123b339b9ae Medium 6.1 Before 2.2.6.2 2.2.6.2 April 20, 2015
CVE-2015-0902 Medium 5 3.0% 2.2.5.1 and earlier 2.2.6 April 3, 2015
CVE-2025-58650 Medium 5.4 0.3% 4.8.7.1 and earlier 4.8.7.2 September 22, 2025
CVE-2026-10755 Medium 5.3 0.3% Before 4.9.9 4.9.9 June 29, 2026
CVE-2023-0585 Medium 4.8 0.8% 4.2.9 and earlier 4.3.0 February 24, 2023
CVE-2026-5075 Medium 4.3 0.3% 0 to 4.9.7 (inclusive) 4.9.7.1 May 20, 2026
CVE-2025-14384 Medium 4.3 0.2% 0 to 4.9.2 (inclusive) 4.9.3 January 16, 2026
CVE-2025-64295 Medium 4.3 0.3% 4.8.6.1 and earlier 4.8.7 November 26, 2025
CVE-2025-12847 Medium 4.3 0.2% 0 to 4.8.9 (inclusive) 4.9.0 November 15, 2025
CVE-2025-58649 Medium 4.3 0.3% 4.8.7.1 and earlier 4.8.7.2 September 22, 2025
WF-dcd7204f-d950-4fb8-beb2-d9f619824fa1 Medium 4.3 2.2.4.1 and earlier 2.2.5 May 31, 2014

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.