Description
The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.
Published: 2026-07-20
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The All in One SEO WordPress plugin provides an AI integration feature accessed through REST API endpoints that should be protected by proper authorization checks. In versions prior to 4.9.9, the plugin fails to enforce correct checks, enabling users with Contributor‑level privileges to call these endpoints and overwrite or reset the site‑wide AI integration state. This vulnerability is classified as CWE‑863: Incorrect Authorization. The impact is limited to modifying the AI integration configuration, without broader access to the site.

Affected Systems

All in One SEO plugin for WordPress, any installation using a version earlier than 4.9.9. The vulnerability affects WordPress sites that have the plugin active, regardless of hosting environment or operating system.

Risk and Exploitability

With a CVSS score of 2.7, the vulnerability is considered low severity. The EPSS score of < 1 % indicates a very low probability of exploitation. It is not listed in the CISA KEV catalog. The attack vector likely requires authenticated access to the WordPress site with a role that has Contributor permissions; network or elevation to higher privileges is not necessary. An attacker with such a role can simply send requests to the affected REST endpoints to alter the AI configuration, but the impact remains limited to the plugin’s scope.

Generated by OpenCVE AI on July 30, 2026 at 19:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to All in One SEO 4.9.9 or later.
  • If immediate upgrade is not possible, remove or restrict the Contributor role so that only users with higher privileges can access the site.
  • Disable or remove the AI integration functionality in the plugin settings to eliminate the vulnerable endpoints.

Generated by OpenCVE AI on July 30, 2026 at 19:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Aioseo
Aioseo all In One Seo
Wordpress
Wordpress wordpress
Vendors & Products Aioseo
Aioseo all In One Seo
Wordpress
Wordpress wordpress

Mon, 20 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Description The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.
Title All in One SEO < 4.9.9 – Contributor+ Incorrect Authorization via AI Integration
References

Subscriptions

Aioseo All In One Seo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-20T13:17:03.527Z

Reserved: 2026-06-03T14:19:40.486Z

Link: CVE-2026-10755

cve-icon Vulnrichment

Updated: 2026-07-20T13:16:55.631Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:00:03Z

Weaknesses