← Back to CVE search

CVE-2026-12082

Praison AI SEO

Description

The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data.

CVSS 7.5EPSS 0.24%Risk 0.77
View source
Published
2026-07-23 07:16:31
Affected versions
<5.0.7
Type
Web application
Last modified
2026-07-23 15:16:33
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N