CVE-2026-10755 PUBLISHED

All in One SEO < 4.9.9 – Contributor+ Incorrect Authorization via AI Integration

Assigner: WPScan
Reserved: 03.06.2026 Published: 20.07.2026 Updated: 20.07.2026

The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.

Product Status

Vendor Unknown
Product All in One SEO
Versions Default: unaffected
  • affected from 0 to 4.9.9 (excl.)

Credits

  • Sudhanshu Chauhan [RedHunt Labs] finder
  • WPScan coordinator

References

Problem Types

  • CWE-863 Incorrect Authorization CWE