SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-12082

HIGH · CVSS 7.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The Praison AI SEO WordPress plugin prior to version 5.0.7 is vulnerable due to the lack of authorization checks on its REST API routes, enabling unauthenticated users to alter the permalinks of published posts and access sensitive configuration data. This vulnerability poses a significant risk to the integrity and confidentiality of WordPress sites utilizing this plugin. WordPress administrators using the affected versions should prioritize updating to mitigate potential exploitation.

CVE
CVE-2026-12082
Severity
HIGH
CVSS
7.5
EPSS
0.24%
WordPress

Original NVD Description

The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data.