CVE-2026-84779
nicheSubscriber-Level Broken Access Control in Agentimus AI SEO WordPress Plugin
CVE-2026-84779 is a broken access control flaw (CWE-862, missing authorization) in the WordPress plugin Agentimus – AI SEO, llms.txt & MCP for AI Agents in all versions up to and including 1.51.0. Because the authorization check is missing or insufficient, any authenticated user with only subscriber-level privileges (CVSS PR:L) can trigger the flaw remotely via a crafted network request with no user interaction. A successful attacker gains unauthorized access to or manipulation of protected plugin functionality, producing high impact on confidentiality and integrity (CVSS 3.1: 8.1 High) with no availability impact. Any WordPress site running the Agentimus plugin at version 1.51.0 or earlier is affected, with sites that allow open subscriber registration facing the greatest risk. There is currently no known exploitation: no public proof-of-concept, no CISA KEV listing, and a low EPSS score of 0.3% (18th percentile).
What to do: WordPress administrators should verify the installed plugin version and update Agentimus to the first release after 1.51.0 as soon as a patched version is published (no fixed version number is given in the advisory). Until then, disable open subscriber registration, review and prune unnecessary subscriber accounts, or temporarily deactivate the plugin. Note that exploitation requires an authenticated subscriber-level account, so sites without open registration are at lower risk.
| Agentimus – AI SEO, llms.txt & MCP for AI Agents (WordPress plugin) | <= 1.51.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt & MCP for AI Agents <= 1.51.0 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.