Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 17 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 15 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Smub
Smub all In One Seo Wordpress Wordpress wordpress |
|
| Vendors & Products |
Smub
Smub all In One Seo Wordpress Wordpress wordpress |
Sat, 15 Nov 2025 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to unauthorized arbitrary media attachment deletion due to a missing authorization check in all versions up to, and including, 4.8.9. This is due to the REST API endpoint `/wp-json/aioseo/v1/ai/image-generator` only verifying that users have the `edit_posts` capability (Contributors and above) without checking if they own or have permission to delete the specific media attachments. This makes it possible for authenticated attackers, with Contributor-level access and above, to permanently delete arbitrary media attachments by ID via the REST API, granted they can determine valid attachment IDs. | |
| Title | All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.8.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Deletion | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:33:27.132Z
Reserved: 2025-11-06T21:04:39.818Z
Link: CVE-2025-12847
Updated: 2025-11-17T18:42:42.215Z
Status : Deferred
Published: 2025-11-15T06:15:43.383
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-12847
No data.
OpenCVE Enrichment
Updated: 2026-04-22T16:45:21Z