CVE-2026-10755

All in One SEO < 4.9.9 – Contributor+ Incorrect Authorization via AI Integration

The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.


We have discovered 864,889 live websites that are affected by CVE-2026-10755.

Run a Free Instant Scan




Affected Software

Product  All in One SEO Pack
Category Search Engine Optimization
Vulnerable Domains864,889 live websites (95% of All in One SEO Pack install base)
Vulnerable Versions
  • from 0 through 4.9.9
Vulnerable Versions Count311 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Jul 20, 2026
  • Updated - Jul 20, 2026

Credits

  • Sudhanshu Chauhan [RedHunt Labs] (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-10755
United States235,908 websites



Japan204,437 websites
Germany56,405 websites
Russia34,871 websites
France31,264 websites
GB30,456 websites
Italy21,523 websites
Poland18,776 websites
Canada14,759 websites

Website Distribution by TLD

Number of websites using CVE-2026-10755
.com406,274 websites
.jp42,208 websites
.org35,282 websites
.net34,170 websites
.ru33,341 websites
.de31,145 websites
.co.jp28,386 websites
.co.uk19,280 websites
.it15,598 websites
.pl14,783 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-10755

Top websites that are affected by CVE-2026-10755. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.net Canada***
******.*******.org United States***
*******.com United States*,***
*********.org United States*,***
*********.com Italy*,***
******.at Germany*,***
************.com United States*,***
*****.com United States*,***
******************.us United States*,***
************.com United States*,***
See full domain list

FAQ

CVE-2026-10755 is Incorrect Authorization in All in One SEO Pack
A total of 864,889 websites have been identified as vulnerable to CVE-2026-10755, based on global website indexing conducted by WebTechSurvey.
The All in One SEO Pack is affected by the CVE-2026-10755 vulnerability.
All in One SEO Pack versions up to 4.9.9 are vulnerable to CVE-2026-10755.
CVE-2026-10755 is resolved in version 4.9.9 of All in One SEO Pack.