Sensitive Data Exposure in All In One SEO Pack by Syed Balkhi
CVE-2025-58649

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2025

What is CVE-2025-58649?

The All In One SEO Pack plugin, developed by Syed Balkhi, is susceptible to a vulnerability that allows attackers to retrieve sensitive data embedded in sent information. This issue impacts various versions of the plugin from n/a up to 4.8.7. Websites using this plugin may unintentionally expose confidential information, which could lead to unauthorized access and potential breaches. It's crucial for users to update to the latest version to mitigate this risk effectively.

Affected Version(s)

All In One SEO Pack <= 4.8.7

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abu Hurayra (Patchstack Alliance)
.