wpseek WordPress Dashboard Tweeter Missing Authorization Vulnerability Allowing Settings Changes

Vulnerability

A missing authorization vulnerability has been identified in the wpseek WordPress Dashboard Tweeter plugin, affecting versions through 1.3.2. This vulnerability arises from incorrectly configured access control security levels, allowing unauthorized users to exploit the issue and change settings.

Impact

Exploitation of this vulnerability could lead to unauthorized changes in plugin settings, potentially allowing for further exploitation or manipulation of the WordPress site.

Remediation

Users of the wpseek WordPress Dashboard Tweeter plugin are advised to update to the latest version. Patchstack has issued a virtual patch to block attacks targeting this vulnerability until an official fix is available.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.