CVE-2026-10755

LOW

All in One SEO < 4.9.9 – Contributor+ Incorrect Authorization via AI Integration

Title source: cna
STIX 2.1

Description

The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/cc4e83e3-b581-4f65-ac2c-24fbfb9da4b3/

Scores

CVSS v3 2.7
EPSS 0.0017
EPSS Percentile 6.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
None/All in One SEO < 4.9.9
Published Jul 20, 2026
Tracked Since Jul 20, 2026