Junglewise Threat Intelligence

CVE-2026-10755: All in One SEO incorrect authorization in AI integration REST API

CVE-2026-10755 · Severity: info · CVSS 2.7 · Published 2026-07-20

Technologies: All in One SEO Pack. Vendors: All in One SEO.

Executive brief

All in One SEO is a popular WordPress plugin used to manage website search engine optimization. A security flaw in the plugin's AI integration features allows users with low-level access, such as guest contributors, to modify or reset the site's AI settings. This could lead to a disruption of AI-driven SEO features or the unauthorized replacement of the site's AI access tokens.

Technical details

An incorrect authorization vulnerability exists in the All in One SEO plugin for WordPress due to insufficient permission checks on specific REST API endpoints. Specifically, the 'aioseo/v1/ai/auth' and 'ai/deactivate' routes are accessible to any authenticated user with 'edit_posts' capabilities (Contributor level and above). An attacker with these low-level credentials can send a POST request to overwrite the 'aiAccessToken' or reset the 'isManuallyConnected' state, effectively hijacking or disabling the site's AI integration. The issue is fixed in version 4.9.9.

Affected products

  • All in One SEO All in One SEO Pack < 4.9.9

Timeline

  • 2026-06-29: disclosed: Public disclosure via WPScan
  • 2026-07-20: advisory: NVD publication date

References