Unauthenticated Broken Access Control in AI for SEO by Patchstack
CVE-2026-66459
6.5MEDIUM
What is CVE-2026-66459?
An unauthenticated broken access control vulnerability has been identified in the AI for SEO plugin, affecting versions 2.4.2 and earlier. This security flaw allows attackers to gain unauthorized access to restricted areas of the application, potentially leading to data exposure or manipulation. It is critical for users of this plugin to update immediately to ensure their sites remain secure.
Affected Version(s)
AI for SEO <= 2.4.2
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ali Osman ERBAS (0110m4n) | Patchstack Bug Bounty Program