CVE-2025-14384: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14384 is a missing authorization vulnerability in the All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress. Due to a missing capability check on the /aioseo/v1/ai/credits REST API route, authenticated attackers with Contributor-level access or above can disclose the site's global AI access token. All plugin versions up to and including 4.9.2 are affected; version 4.9.3 introduces the fix. It carries a CVSS v3.1 base score of 4.3 (Medium) (Feedly, Wordfence).

Technical details

The root cause is classified as CWE-862 (Missing Authorization): the REST endpoint /aioseo/v1/ai/credits does not enforce a capability check before returning the global AI access token, meaning any authenticated WordPress user at Contributor level or higher can query it directly. Exploitation requires only a valid WordPress account and a simple authenticated HTTP GET request to the vulnerable REST route — no special tools or complex payloads are needed. The token returned is a shared, site-wide credential used to interact with an external AI API, making its exposure a straightforward information disclosure issue (Wordfence, Feedly).

Impact

Successful exploitation results in the disclosure of the site's global AI access token, which could allow an attacker to make unauthorized API calls against the associated AI service, consuming the site owner's credits or quota. The confidentiality impact is limited to this token; there is no direct integrity or availability impact on the WordPress installation itself. However, depending on the AI service provider's permissions model, a leaked token could potentially be used to access or manipulate AI-generated content or billing resources outside the WordPress context (Wordfence, Feedly).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.03%, indicating a very low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum a Contributor-level WordPress account, limiting the attacker pool to authenticated users (Feedly, Wordfence).

Exploitation steps

  1. Obtain a low-privileged account: Register or obtain a Contributor-level (or higher) account on the target WordPress site running All in One SEO ≤ 4.9.2.
  2. Authenticate: Log in to the WordPress site and obtain a valid authentication nonce or use application passwords/cookie-based authentication for REST API access.
  3. Query the vulnerable endpoint: Send an authenticated HTTP GET request to https://<target-site>/wp-json/aioseo/v1/ai/credits, including the WordPress authentication cookie or Authorization header.
  4. Extract the AI token: Parse the JSON response, which will contain the site's global AI access token due to the missing capability check.
  5. Abuse the token: Use the extracted token to make unauthorized calls to the associated AI API service, consuming the site owner's credits or accessing AI features outside the intended scope (Wordfence).

Indicators of compromise

  • Network: Unusual or repeated authenticated GET requests to /wp-json/aioseo/v1/ai/credits from Contributor-level user accounts, especially from unexpected IP addresses or at unusual times.
  • Logs: WordPress access logs showing requests to the /aioseo/v1/ai/credits REST endpoint by low-privileged users; multiple requests from the same user in a short timeframe.
  • AI Service: Unexpected spikes in AI API credit consumption or API calls originating from the site's token that do not correspond to legitimate editorial activity.

Mitigation and workarounds

Update the All in One SEO plugin to version 4.9.3 or later, which adds the missing capability check to the /aioseo/v1/ai/credits REST endpoint. Site administrators should also rotate any AI access tokens that may have been exposed while running a vulnerable version. If immediate update is not possible, restricting Contributor-level registrations or disabling the REST API for unauthenticated/low-privileged users via a security plugin can reduce exposure (Wordfence, Plugin Changeset).

Community reactions

Wordfence published the vulnerability details in their threat intelligence database, and Sucuri included it in their January 2026 vulnerability patch roundup, noting it as a routine disclosure requiring prompt patching (Sucuri Blog, Wordfence). Community reaction has been minimal given the low severity and limited exploitation potential.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management