Impact
The All in One SEO WordPress plugin provides an AI integration feature accessed through REST API endpoints that should be protected by proper authorization checks. In versions prior to 4.9.9, the plugin fails to enforce correct checks, enabling users with Contributor‑level privileges to call these endpoints and overwrite or reset the site‑wide AI integration state. This vulnerability is classified as CWE‑863: Incorrect Authorization. The impact is limited to modifying the AI integration configuration, without broader access to the site.
Affected Systems
All in One SEO plugin for WordPress, any installation using a version earlier than 4.9.9. The vulnerability affects WordPress sites that have the plugin active, regardless of hosting environment or operating system.
Risk and Exploitability
With a CVSS score of 2.7, the vulnerability is considered low severity. The EPSS score of < 1 % indicates a very low probability of exploitation. It is not listed in the CISA KEV catalog. The attack vector likely requires authenticated access to the WordPress site with a role that has Contributor permissions; network or elevation to higher privileges is not necessary. An attacker with such a role can simply send requests to the affected REST endpoints to alter the AI configuration, but the impact remains limited to the plugin’s scope.
OpenCVE Enrichment