CVE-2026-12082 PUBLISHED

Praison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure)

Assigner: WPScan
Reserved: 12.06.2026 Published: 23.07.2026 Updated: 23.07.2026

The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data.

Product Status

Vendor Unknown
Product Praison AI SEO
Versions Default: unaffected
  • affected from 0 to 5.0.7 (excl.)

Credits

  • Shivamani Vastrala finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE