CVE-2020-35946: Semperplugins All In One Seo Pack
Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.
An issue was discovered in the All in One SEO Pack plugin before 3.6.2 for WordPress. The SEO Description and Title fields are vulnerable to unsanitized input from a Contributor, leading to stored XSS.
Affected products
- Semperplugins All In One Seo Pack: before 3.6.2 (fixed in 3.6.2)
Published 2021-01-01. Last modified 2026-06-17.