Impact
The Praison AI SEO WordPress plugin version 5.0.6 and earlier fails to enforce authorization on several REST API endpoints. As a result, an unauthenticated user can modify the permalink of any published post and read the plugin’s configuration data. Changing a permalink can break links, disrupt search‑engine rankings, and redirect users to attacker‑controlled destinations. Exposure of configuration information may reveal sensitive settings or credentials that could be leveraged in further attacks.
Affected Systems
Any WordPress installation that has the Praison AI SEO plugin installed with a version earlier than 5.0.7 is vulnerable. The issue applies to all users of the plugin regardless of role or permissions.
Risk and Exploitability
The vulnerability is rated with a CVSS score of 7.5 (High) and an EPSS score of less than 1 %, indicating that while the likelihood of exploitation is low, it remains a valid concern for websites that keep the plugin out of date. The attack vector is remote and unauthenticated via the WordPress REST API, meaning anyone with internet access to the site can exploit it. The lack of KEV listing suggests no known large‑scale exploitation, but the potential for damage warrants immediate attention.
OpenCVE Enrichment