SiteSEO SEO Simplified WordPress Plugin Improper Authorization Vulnerability Allowing Settings Reset

Vulnerability

A vulnerability exists in the SiteSEO – SEO Simplified plugin for WordPress, in all versions through 1.3.2. The issue arises from an incorrect capability check in the 'siteseo_reset_settings' function, allowing authenticated attackers with access to certain SiteSEO settings capabilities to reset the plugin's settings. This unauthorized data modification could disrupt user configurations and SEO strategies managed through the plugin.

Impact

Exploitation of this vulnerability allows for unauthorized resetting of the SiteSEO plugin's settings, potentially disrupting configured SEO strategies and website visibility.

Remediation

Users can update to version 1.3.3 or a newer patched version to address this vulnerability.

Added: Nov 19, 2025, 6:25 AM
Updated: Nov 19, 2025, 6:25 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.9
remediation
7.7
relevance
1.1
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.