Description
The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data.
Published: 2026-07-23
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Praison AI SEO WordPress plugin version 5.0.6 and earlier fails to enforce authorization on several REST API endpoints. As a result, an unauthenticated user can modify the permalink of any published post and read the plugin’s configuration data. Changing a permalink can break links, disrupt search‑engine rankings, and redirect users to attacker‑controlled destinations. Exposure of configuration information may reveal sensitive settings or credentials that could be leveraged in further attacks.

Affected Systems

Any WordPress installation that has the Praison AI SEO plugin installed with a version earlier than 5.0.7 is vulnerable. The issue applies to all users of the plugin regardless of role or permissions.

Risk and Exploitability

The vulnerability is rated with a CVSS score of 7.5 (High) and an EPSS score of less than 1 %, indicating that while the likelihood of exploitation is low, it remains a valid concern for websites that keep the plugin out of date. The attack vector is remote and unauthenticated via the WordPress REST API, meaning anyone with internet access to the site can exploit it. The lack of KEV listing suggests no known large‑scale exploitation, but the potential for damage warrants immediate attention.

Generated by OpenCVE AI on August 3, 2026 at 22:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Praison AI SEO to version 5.0.7 or later, which adds the missing authorization checks.
  • If an upgrade is not immediately possible, restrict external access to the WordPress REST API routes used by the plugin or place the site behind authentication controls such as a VPN or web‑application firewall.
  • Audit the site for unintended permalink changes and verify that configuration data has not been exposed to unauthorized users.

Generated by OpenCVE AI on August 3, 2026 at 22:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Praison Ai
Praison Ai praison Ai Seo
Wordpress
Wordpress wordpress
Vendors & Products Praison Ai
Praison Ai praison Ai Seo
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data.
Title Praison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure)
References

Subscriptions

Praison Ai Praison Ai Seo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-23T14:12:30.060Z

Reserved: 2026-06-12T12:57:22.525Z

Link: CVE-2026-12082

cve-icon Vulnrichment

Updated: 2026-07-23T14:12:25.581Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T07:16:31.423

Modified: 2026-07-23T15:16:33.560

Link: CVE-2026-12082

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:00:04Z

Weaknesses