All in One SEO <= 5.0.2.1 - Authenticated (Contributor+) Missing Authorization to Image Attachment Creation and Limited Image Disclosure via AI Image Generation
- ID
- WPSEC-2026-0655
- Plugin
- All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) (all-in-one-seo-pack)
- Affected
- from 4.8.8 before 5.0.3
- Remediation
- Update to 5.0.3 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Weakness
- CWE-862
- Usage
- Plugin High · Affected versions High among sites WPSec scans, 2026-10-08
- Attack surface
- All in One SEO on WPSec AttackSurface
- Fix released
- Published
Description
The All in One SEO plugin for WordPress is vulnerable to unauthorized access via the AI image generation REST endpoint in versions 4.8.8 up to, and including, 5.0.2.1. The endpoint checked only that the caller could edit the target post. It did not check the upload_files capability, and it did not check whether the caller could view the attachment supplied as the source image for an edit. This makes it possible for authenticated attackers with Contributor-level access and above, who normally cannot upload files, to add AI-generated images to the media library, attached to their own posts, using the site's AI credits, and to receive AI-generated edits of images attached to posts they cannot view, such as other users' drafts or private posts.
References
- https://wpsec.com/vuln/WPSEC-2026-0655/
- https://plugins.svn.wordpress.org/all-in-one-seo-pack/tags/5.0.3/
- https://wordpress.org/plugins/all-in-one-seo-pack/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS