Plugin is vulnerable to unauthorized access of data due to a missing capability check on the `/aioseo/v1/ai/credits` REST route. This makes it possible for authenticated attackers, with Contributor-level access and above, to disclose the global AI access token. This vulnerability affects the following application versions: All in One SEO Pack... Weiterlesen
Intelligence View
Missing Authorization to Authenticated (Contributor+) AI Access Token and Credit Disclosure
Plugin is vulnerable to unauthorized access of data due to a missing capability check on the `/aioseo/v1/ai/credits` REST route. This makes it possible for authenticated attackers, with Contributor-level access and above, to disclose the…
SOCIAL SHARE CARD GENERATOR