CVE-2025-14384
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2026-01-16

Last updated on: 2026-01-16

Assigner: Wordfence

Description
The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `/aioseo/v1/ai/credits` REST route in all versions up to, and including, 4.9.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to disclose the global AI access token.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-16
Last Modified
2026-01-16
Generated
2026-06-16
AI Q&A
2026-01-16
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
semperfi webmaster to 4.9.2 (inc)
semperfi webmaster 4.9.3
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the All in One SEO plugin for WordPress, where a missing capability check on the /aioseo/v1/ai/credits REST route allows authenticated users with Contributor-level access or higher to access sensitive data. Specifically, these users can disclose the global AI access token without proper authorization.

Impact Analysis

The impact of this vulnerability is that an attacker with Contributor-level access or above can obtain the global AI access token, which could potentially be used to access or manipulate AI-related features or data within the plugin. This unauthorized disclosure could lead to misuse of AI services or compromise of related data.

Mitigation Strategies

Update the All in One SEO plugin to version 4.9.3 or later, as this version includes a comprehensive update that likely addresses the vulnerability. Until the update is applied, restrict Contributor-level access and above to trusted users only to reduce the risk of unauthorized data disclosure. [2]

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-14384. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart