Vulnerabilities / All in One SEO / WPSEC-2026-0655

All in One SEO <= 5.0.2.1 - Authenticated (Contributor+) Missing Authorization to Image Attachment Creation and Limited Image Disclosure via AI Image Generation

Medium 5.4 CWE-862Fixed in 5.0.3
ID
WPSEC-2026-0655
Plugin
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) (all-in-one-seo-pack)
Affected
from 4.8.8 before 5.0.3
Remediation
Update to 5.0.3 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Weakness
CWE-862
Usage
Plugin High · Affected versions High among sites WPSec scans, 2026-10-08
Attack surface
All in One SEO on WPSec AttackSurface
Fix released
Published

Description

The All in One SEO plugin for WordPress is vulnerable to unauthorized access via the AI image generation REST endpoint in versions 4.8.8 up to, and including, 5.0.2.1. The endpoint checked only that the caller could edit the target post. It did not check the upload_files capability, and it did not check whether the caller could view the attachment supplied as the source image for an edit. This makes it possible for authenticated attackers with Contributor-level access and above, who normally cannot upload files, to add AI-generated images to the media library, attached to their own posts, using the site's AI credits, and to receive AI-generated edits of images attached to posts they cannot view, such as other users' drafts or private posts.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0