Executive brief
Agentimus is a WordPress plugin that provides AI-powered SEO optimization and agent capabilities. The plugin contains a broken access control vulnerability that allows subscribers (low-privilege users) to access pages and perform actions they should not be permitted to do, potentially exposing sensitive data or allowing unauthorized modifications.
Technical details
This broken access control vulnerability in Agentimus plugin versions up to 1.51.0 allows users with subscriber-level privileges to access restricted functionality through improper authorization checks on API endpoints. The vulnerability affects multiple related API routes and can be exploited by authenticated attackers with minimal privileges. According to Patchstack's mitigation notes, bearer-authenticated requests to vulnerable sibling routes were blocked as a defensive measure. The issue was patched in version 1.51.1.
Affected products
- Agentimus AI SEO, llms.txt & MCP for AI Agents <= 1.51.0
Timeline
- 2026-09-03: disclosed: Vulnerability disclosed
- 2026-09-03: patched: Patched in version 1.51.1