CVE-2026-12082

CVE-2026-12082CVE-2026-12082

Description

The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data.

Scoring

CVSS 7.5 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Last modified2026-07-23
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.