CVE-2026-10755
LOW Exploitation: PoC
2.7
CVSS 3.1
Description
The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.
Metadata
Severity & Metrics
2.7
LOW CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Unknown | All in One SEO | — | 0 < 4.9.9 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | CWE-863 Incorrect Authorization |
| CWE-863 | adp | CWE-863 Incorrect Authorization |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 2.7 | LOW | 3.1 | adp | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N |