All in One SEO
cpe:2.3:a:aioseo:all_in_one_seo:*:*:*:*:wordpress:*:*
- < 4.9.9
A vulnerability exists in the All in One SEO WordPress plugin in versions prior to 4.9.9, where access to certain AI integration REST API endpoints is not properly restricted. This flaw allows users with low-level privileges, such as Contributors, to overwrite or reset the site-wide AI integration state.
Exploitation of this vulnerability allows for unauthorized users to modify the site's AI integration settings, potentially disrupting AI-related functionalities or workflows.
To reproduce this vulnerability, log in as a Contributor and capture the session cookies. Then, obtain a valid WordPress REST API nonce from a page that includes the wpApiSettings. With the nonce, send a POST request to the 'aioseo/v1/ai/auth' endpoint to overwrite the global AI access token, or use the 'aioseo/v1/ai/deactivate' endpoint to reset the site's AI integration state.
Users are advised to update the All in One SEO WordPress plugin to version 4.9.9 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.