← Browse

CVE-2026-12082

Medium

Elevated severity or exploit probability.

CVSS base
7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS — probability of exploitation (30 days)
0.4%
34.6th percentile
CISA KEV
Not listed
Weakness / dates
CWE-862
Published 2026-07-23 · modified 2026-07-23

Description

The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data.

References

Official: NVD · CVE.org