logo

All In One SEO Plugin Flaw Exposes AI Token to Low-Privilege WordPress Users

ID: 1f68d412-22d6-50c1-8b74-7af32c1976bd

STIX ID: report--1f68d412-22d6-50c1-8b74-7af32c1976bd

Feed Name: The Cyber Express

Threat Score
60/100

Date Published: 2026-01-19

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

A missing permission check in the All In One SEO (AIOSEO) WordPress plugin allowed low-privileged Contributor accounts to retrieve a site-wide AI access token, risking unauthorized AI usage, quota exhaustion, and unexpected costs; the issue affected versions up to 4.9.2 and was fixed in 4.9.3, and site owners are advised to update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.