Junglewise Threat Intelligence

CVE-2026-84779: Agentimus AI SEO broken access control

CVE-2026-84779 · Severity: high · CVSS 8.1 · Published 2026-09-03

Executive brief

Agentimus is a WordPress plugin that provides AI-powered SEO optimization and agent capabilities. The plugin contains a broken access control vulnerability that allows subscribers (low-privilege users) to access pages and perform actions they should not be permitted to do, potentially exposing sensitive data or allowing unauthorized modifications.

Technical details

This broken access control vulnerability in Agentimus plugin versions up to 1.51.0 allows users with subscriber-level privileges to access restricted functionality through improper authorization checks on API endpoints. The vulnerability affects multiple related API routes and can be exploited by authenticated attackers with minimal privileges. According to Patchstack's mitigation notes, bearer-authenticated requests to vulnerable sibling routes were blocked as a defensive measure. The issue was patched in version 1.51.1.

Affected products

  • Agentimus AI SEO, llms.txt & MCP for AI Agents <= 1.51.0

Timeline

  • 2026-09-03: disclosed: Vulnerability disclosed
  • 2026-09-03: patched: Patched in version 1.51.1

References