Unauthorized Media Deletion in All in One SEO Plugin for WordPress
CVE-2025-12847

4.3MEDIUM

What is CVE-2025-12847?

The All in One SEO plugin for WordPress features a security flaw that permits unauthorized deletion of media attachments. This issue arises from a missing authorization check within the REST API endpoint /wp-json/aioseo/v1/ai/image-generator used by the plugin. The API only verifies whether a user has the edit_posts capability, allowing authenticated users with Contributor-level access or higher to delete media attachments without proper permissions. Attackers can exploit this flaw to gain control over arbitrary media attachments by knowing valid attachment IDs, potentially leading to loss of critical media content.

Affected Version(s)

All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic * <= 4.8.9

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Angus Girvan
.
CVE-2025-12847 : Unauthorized Media Deletion in All in One SEO Plugin for WordPress