CVE-2026-10755

The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-20 07:16

Updated : 2026-07-21 18:51


NVD link : CVE-2026-10755

Mitre link : CVE-2026-10755

CVE.ORG link : CVE-2026-10755


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization