ZeroHour

CVE-2026-84779

niche

Subscriber-Level Broken Access Control in Agentimus AI SEO WordPress Plugin

CVSS 3.1
8.1 high
EPSS
<1%p18
Published
()
Modified
AI analysis

CVE-2026-84779 is a broken access control flaw (CWE-862, missing authorization) in the WordPress plugin Agentimus – AI SEO, llms.txt & MCP for AI Agents in all versions up to and including 1.51.0. Because the authorization check is missing or insufficient, any authenticated user with only subscriber-level privileges (CVSS PR:L) can trigger the flaw remotely via a crafted network request with no user interaction. A successful attacker gains unauthorized access to or manipulation of protected plugin functionality, producing high impact on confidentiality and integrity (CVSS 3.1: 8.1 High) with no availability impact. Any WordPress site running the Agentimus plugin at version 1.51.0 or earlier is affected, with sites that allow open subscriber registration facing the greatest risk. There is currently no known exploitation: no public proof-of-concept, no CISA KEV listing, and a low EPSS score of 0.3% (18th percentile).

What to do: WordPress administrators should verify the installed plugin version and update Agentimus to the first release after 1.51.0 as soon as a patched version is published (no fixed version number is given in the advisory). Until then, disable open subscriber registration, review and prune unnecessary subscriber accounts, or temporarily deactivate the plugin. Note that exploitation requires an authenticated subscriber-level account, so sites without open registration are at lower risk.

Affected
Agentimus – AI SEO, llms.txt & MCP for AI Agents (WordPress plugin)<= 1.51.0
Estimated exposure
nichelikely low thousands of installs or fewer (no public active-install figures available for this specialized, recently released plugin) — The plugin targets the recently emerged llms.txt/MCP-for-AI-agents trend, which suggests limited adoption, and no active-install counts or internet-exposure scan data were provided, so this is an order-of-magnitude estimate rather than a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt & MCP for AI Agents <= 1.51.0 versions.

Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.