All in One SEO WordPress Plugin Missing Authorization Vulnerability Allowing Data Disclosure

Vulnerability

A vulnerability exists in the All in One SEO WordPress plugin, specifically in the 'Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic' version 4.9.2 and prior. The issue arises from a missing capability check on the '/aioseo/v1/ai/credits' REST route, which allows authenticated attackers with Contributor-level access and above to access and disclose the global AI access token.

Impact

Exploitation of this vulnerability allows for unauthorized disclosure of the global AI access token.

Remediation

Users can update to version 4.9.3 or a newer patched version to address this vulnerability.

Added: Jan 16, 2026, 5:23 AM
Updated: Jan 16, 2026, 5:23 AM

Vulnerability Rating

Custom Algorithm
spread
7.6
impact
2.5
exploitability
6.1
remediation
7.7
relevance
2.1
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.