Improper access control in All in One SEO Pack - #VU59090
Published: December 23, 2021
All in One SEO Pack
Michael Torbert
Description
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to a logic error that allowed using case-sensitive URLs in REST API calls. A remote low-privileged user (e.g. with subscriber privilege) can request any protected REST API endpoint by changing a single character to uppercase in the URL.