All in One SEO plugin, used by more than 3 million websites, has two security holes. Privilege-escalation bug and an SQL-injection problem are ripe for easy exploitation, researchers say. Users should upgrade to the patched version of the plugin, v. 4.1.5.3.0 and v.4.2. The bug carries a critical rating of 9.9 out of 10 on the CVSS vulnerability-severity scale, due to its ease of exploitation.”]
Source: https://threatpost.com/all-in-one-seo-plugin-bug-threatens-3m-wordpress-websites-takeovers/177240/