Impact
The vulnerability constitutes an unauthenticated broken access control flaw in the AI for SEO plugin up to version 2.4.2. An attacker who can reach the plugin’s HTTP endpoints can perform actions normally restricted to authorized administrators, potentially modifying settings, retrieving internal data or executing arbitrary plugin functions. The weakness allows the attacker to gain unauthorized access to configuration and content management functions, thereby impacting the confidentiality and integrity of the WordPress site. Based on the description, it is inferred that the attack vector is reaching those endpoints from any location that can access the WordPress site.
Affected Systems
Affected systems are WordPress sites that have the AI for SEO plugin installed from Space Codes, specifically versions 2.4.2 and earlier. No other products or vendors are listed as affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability, and the EPSS score is not available. The vulnerability is not currently listed in CISA’s KEV catalog, but the lack of a known exploit does not negate the potential risk. Attackers can exploit this flaw without authentication, making it trivially reachable from any location that can reach the WordPress site. The risk is that an adversary can gain administrative-level control over the plugin, leading to data leakage, site compromise or further exploitation through other plugin functionalities.
OpenCVE Enrichment