SiteSEO SEO Simplified WordPress Plugin Improper Authorization Vulnerability Allowing Settings Reset
Vulnerability
A vulnerability exists in the SiteSEO – SEO Simplified plugin for WordPress, in all versions through 1.3.2. The issue arises from an incorrect capability check in the 'siteseo_reset_settings' function, allowing authenticated attackers with access to certain SiteSEO settings capabilities to reset the plugin's settings. This unauthorized data modification could disrupt user configurations and SEO strategies managed through the plugin.
Impact
Exploitation of this vulnerability allows for unauthorized resetting of the SiteSEO plugin's settings, potentially disrupting configured SEO strategies and website visibility.
Remediation
Users can update to version 1.3.3 or a newer patched version to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
