CVE-2026-10755
Received Received - Intake

All in One SEO AI Integration State Modification via REST API

Vulnerability report for CVE-2026-10755, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-20

Assigner: WPScan

Description

The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-20
Generated
2026-07-21
AI Q&A
2026-07-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
aioseo all_in_one_seo to 4.9.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-10755 is a vulnerability in the All in One SEO WordPress plugin before version 4.9.9. It allows users with low-level privileges, such as Contributors, to overwrite or reset the site-wide AI integration state by exploiting improperly restricted REST API endpoints.

Detection Guidance

Check if users with Contributor-level privileges can access or modify the AI integration REST API endpoints. Monitor requests to aioseo/v1/ai/auth and aioseo/v1/ai/deactivate endpoints. Review logs for unauthorized changes to AI integration settings.

Impact Analysis

An attacker with a Contributor account could replace the AI access token or reset the AI integration, potentially disrupting AI features or causing unintended behavior on the website.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR or HIPAA if the AI integration state includes or processes personal or sensitive data. Unauthorized access to AI endpoints might lead to data exposure or unauthorized modifications, violating confidentiality or integrity requirements under these regulations.

Mitigation Strategies

Update the All in One SEO plugin to version 4.9.9 or later. Restrict Contributor-level users from accessing sensitive API endpoints. Review and audit user roles and permissions to ensure least privilege access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10755. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart