CVE-2026-84779

8.1

Sheikh Heera · Agentimus – AI SEO, llms.txt & MCP for AI Agents

A broken access control vulnerability in the Agentimus plugin allows authenticated subscribers to perform unauthorized actions, potentially leading to unauthorized data modification or access.

Executive summary

A high-severity broken access control flaw in the Agentimus WordPress plugin allows authenticated subscribers to bypass authorization checks, creating significant risk for site integrity.

Vulnerability

This vulnerability involves a missing authorization check (CWE-862) that permits users with subscriber-level privileges to access restricted functions. The attack vector is network-based and requires a low-privileged authenticated user to trigger the flaw.

Business impact

The ability for low-privileged subscribers to bypass access controls can result in unauthorized modification of site settings or data, potentially affecting SEO configurations or LLM integrations. Given the CVSS score of 8.1, this vulnerability poses a high risk to the confidentiality and integrity of the WordPress environment, necessitating immediate attention to prevent unauthorized administrative actions.

Remediation

Immediate Action: Update the Agentimus – AI SEO, llms.txt & MCP for AI Agents plugin to version 1.51.1 or the latest available version provided by the vendor.

Proactive Monitoring: Review WordPress user activity logs for suspicious requests originating from subscriber accounts that involve administrative or configuration-related endpoints.

Compensating Controls: Implement a Web Application Firewall (WAF) rule to block unauthorized attempts to access plugin-specific administrative endpoints by non-administrative users.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a significant security oversight that could lead to unauthorized administrative control within the WordPress application. Security teams should prioritize updating the affected plugin immediately to version 1.51.1, as this is the only definitive way to enforce proper authorization boundaries and mitigate the risk of unauthorized data or configuration changes.

Sources

Originally found and disclosed by Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program, per the CVE Program record.