Executive brief
The All in One SEO plugin for WordPress, which helps websites optimize their content for search engines, contains a security flaw that exposes sensitive internal data. This vulnerability allows users with low-level access, such as contributors, to view private information like API keys, OAuth tokens, and license details. An attacker could use this information to gain unauthorized access to connected services or compromise the site's SEO management tools.
Technical details
The vulnerability is classified as an Exposure of Sensitive Information (CWE-200) within the All in One SEO plugin for WordPress. It stems from the 'internalOptions' localized script data being passed to the WordPress wp_localize_script() function in post editor contexts without proper masking or privilege checks. Authenticated attackers with at least contributor-level permissions can access the post editor and view the page source to retrieve sensitive internal configuration data, including API/OAuth tokens and license-related values. The issue is present in versions up to 4.9.7 and has been addressed in subsequent updates.
Affected products
- All in One SEO All in One SEO up to, and including, 4.9.7
Timeline
- 2026-05-20: disclosed: NVD publication date
- 2026-05-20: advisory: Wordfence advisory published