Medium severity5.4NVD Advisory· Published Oct 16, 2019· Updated Jun 17, 2026
CVE-2019-16520
CVE-2019-16520
Description
The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to improper encoding of the SEO-specific description for posts provided by the plugin via unsafe placeholder replacement.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:semperplugins:all_in_one_seo_pack:*:*:*:*:*:wordpress:*:*Range: <3.2.7
- WordPress/all-in-one-seo-pack plugindescription
- Range: <3.2.7
- Range: <3.2.7
Patches
Vulnerability mechanics
References
6- github.com/semperfiwebdesign/all-in-one-seo-pack/issues/2888nvdPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2019/10/16/5nvdExploitMailing ListThird Party Advisory
- github.com/sbaresearch/advisories/tree/public/2019/SBA-ADV-20190913-04_WordPress_Plugin_All_in_One_SEO_PacknvdExploitThird Party Advisory
- semperplugins.com/all-in-one-seo-pack-changelog/nvdRelease NotesVendor Advisory
- wordpress.org/plugins/all-in-one-seo-pack/nvdProductThird Party Advisory
- wpvulndb.com/vulnerabilities/9915nvdThird Party Advisory
News mentions
0No linked articles in our index yet.