Unauthorized Media Deletion in All in One SEO Plugin for WordPress
CVE-2025-12847
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 November 2025
What is CVE-2025-12847?
The All in One SEO plugin for WordPress features a security flaw that permits unauthorized deletion of media attachments. This issue arises from a missing authorization check within the REST API endpoint /wp-json/aioseo/v1/ai/image-generator used by the plugin. The API only verifies whether a user has the edit_posts capability, allowing authenticated users with Contributor-level access or higher to delete media attachments without proper permissions. Attackers can exploit this flaw to gain control over arbitrary media attachments by knowing valid attachment IDs, potentially leading to loss of critical media content.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
All in One SEO β Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic * <= 4.8.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved