Junglewise Threat Intelligence

CVE-2026-39697: HBSS Technologies MAIO Broken Access Control in WordPress

CVE-2026-39697 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

HBSS Technologies MAIO, a WordPress plugin used for AI-driven SEO and geographic optimization, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to perform actions that should be restricted to higher-level users. While the immediate risk is considered medium, it could allow attackers to modify site configurations or content without permission.

Technical details

The MAIO – The new AI GEO / SEO tool plugin for WordPress (versions up to and including 6.2.8) suffers from a Broken Access Control vulnerability (CWE-862). The flaw stems from missing authorization checks or incorrectly configured security levels within the plugin's functional components. An unauthenticated remote attacker can exploit this by sending crafted network requests to execute actions that should require administrative or elevated privileges. This can lead to unauthorized data modification or configuration changes. As of the advisory date, no official patch has been confirmed, though users are advised to monitor for updates from HBSS Technologies.

Affected products

  • HBSS Technologies MAIO – The new AI GEO / SEO tool <= 6.2.8

Timeline

  • 2026-01-28: other: Vulnerability reported by researcher Legion Hunter
  • 2026-02-27: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE-2026-39697 published

References