Description
Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions.
Published: 2026-08-13
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability constitutes an unauthenticated broken access control flaw in the AI for SEO plugin up to version 2.4.2. An attacker who can reach the plugin’s HTTP endpoints can perform actions normally restricted to authorized administrators, potentially modifying settings, retrieving internal data or executing arbitrary plugin functions. The weakness allows the attacker to gain unauthorized access to configuration and content management functions, thereby impacting the confidentiality and integrity of the WordPress site. Based on the description, it is inferred that the attack vector is reaching those endpoints from any location that can access the WordPress site.

Affected Systems

Affected systems are WordPress sites that have the AI for SEO plugin installed from Space Codes, specifically versions 2.4.2 and earlier. No other products or vendors are listed as affected.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity vulnerability, and the EPSS score is not available. The vulnerability is not currently listed in CISA’s KEV catalog, but the lack of a known exploit does not negate the potential risk. Attackers can exploit this flaw without authentication, making it trivially reachable from any location that can reach the WordPress site. The risk is that an adversary can gain administrative-level control over the plugin, leading to data leakage, site compromise or further exploitation through other plugin functionalities.

Generated by OpenCVE AI on August 13, 2026 at 17:22 UTC.

Remediation

Vendor Solution

Update the WordPress AI for SEO plugin to the latest available version (at least 2.4.3).


OpenCVE Recommended Actions

  • Release the WordPress AI for SEO plugin to the latest available version (at least 2.4.3).
  • If an upgrade cannot be performed immediately, disable or remove the plugin from the WordPress installation to eliminate the exposure.
  • Configure Web Application Firewall rules to block or rate‑limit suspicious requests to the plugin’s endpoints until the issue is resolved.

Generated by OpenCVE AI on August 13, 2026 at 17:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions.
Title WordPress AI for SEO plugin <= 2.4.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:28:49.306Z

Reserved: 2026-07-27T09:00:34.597Z

Link: CVE-2026-66459

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T14:17:06.973

Modified: 2026-08-13T16:18:44.343

Link: CVE-2026-66459

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T17:30:07Z

Weaknesses