{
 "id": "WPSEC-2026-0655",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0655/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0655/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0655/index.md",
 "title": "All in One SEO <= 5.0.2.1 - Authenticated (Contributor+) Missing Authorization to Image Attachment Creation and Limited Image Disclosure via AI Image Generation",
 "description": "The All in One SEO plugin for WordPress is vulnerable to unauthorized access via the AI image generation REST endpoint in versions 4.8.8 up to, and including, 5.0.2.1. The endpoint checked only that the caller could edit the target post. It did not check the upload_files capability, and it did not check whether the caller could view the attachment supplied as the source image for an edit. This makes it possible for authenticated attackers with Contributor-level access and above, who normally cannot upload files, to add AI-generated images to the media library, attached to their own posts, using the site's AI credits, and to receive AI-generated edits of images attached to posts they cannot view, such as other users' drafts or private posts.",
 "plugin": {
  "slug": "all-in-one-seo-pack",
  "name": "All in One SEO",
  "full_name": "All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)",
  "wordpress_org": "https://wordpress.org/plugins/all-in-one-seo-pack/",
  "advisories_url": "https://wpsec.com/vuln/plugin/all-in-one-seo-pack/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/all-in-one-seo-pack"
 },
 "type": "NO AUTHORISATION",
 "cwe": [
  "CWE-862"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.4,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "4.8.8",
    "from_inclusive": true,
    "to": "5.0.3",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 4.8.8 before 5.0.3"
  ]
 },
 "introduced_in": "4.8.8",
 "fixed_in": "5.0.3",
 "remediation": "Update to 5.0.3 or later.",
 "fix_released": "2026-10-07T14:05:22+00:00",
 "published": "2026-10-08T14:54:41+00:00",
 "updated": "2026-10-07T18:24:38.403724+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0655/",
  "https://plugins.svn.wordpress.org/all-in-one-seo-pack/tags/5.0.3/",
  "https://wordpress.org/plugins/all-in-one-seo-pack/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/all-in-one-seo-pack",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "High",
  "affected_versions": "High",
  "as_of": "2026-10-08"
 }
}