CVE-2020-35946: Semperplugins All In One Seo Pack

Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue was discovered in the All in One SEO Pack plugin before 3.6.2 for WordPress. The SEO Description and Title fields are vulnerable to unsanitized input from a Contributor, leading to stored XSS.

Affected products

Published 2021-01-01. Last modified 2026-06-17.