Executive brief
All in One SEO is a popular WordPress plugin used to manage website search engine optimization. A security flaw in the plugin's AI integration features allows users with low-level access, such as guest contributors, to modify or reset the site's AI settings. This could lead to a disruption of AI-driven SEO features or the unauthorized replacement of the site's AI access tokens.
Technical details
An incorrect authorization vulnerability exists in the All in One SEO plugin for WordPress due to insufficient permission checks on specific REST API endpoints. Specifically, the 'aioseo/v1/ai/auth' and 'ai/deactivate' routes are accessible to any authenticated user with 'edit_posts' capabilities (Contributor level and above). An attacker with these low-level credentials can send a POST request to overwrite the 'aiAccessToken' or reset the 'isManuallyConnected' state, effectively hijacking or disabling the site's AI integration. The issue is fixed in version 4.9.9.
Affected products
- All in One SEO All in One SEO Pack < 4.9.9
Timeline
- 2026-06-29: disclosed: Public disclosure via WPScan
- 2026-07-20: advisory: NVD publication date