Unauthorized Media Deletion in All in One SEO Plugin for WordPress
CVE-2025-12847
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 November 2025
What is CVE-2025-12847?
The All in One SEO plugin for WordPress features a security flaw that permits unauthorized deletion of media attachments. This issue arises from a missing authorization check within the REST API endpoint /wp-json/aioseo/v1/ai/image-generator used by the plugin. The API only verifies whether a user has the edit_posts capability, allowing authenticated users with Contributor-level access or higher to delete media attachments without proper permissions. Attackers can exploit this flaw to gain control over arbitrary media attachments by knowing valid attachment IDs, potentially leading to loss of critical media content.
Affected Version(s)
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic * <= 4.8.9