WP-GeoMeta Privilege Escalation Vulnerability in WordPress

Vulnerability

A privilege escalation vulnerability has been identified in the WP-GeoMeta plugin for WordPress, specifically in versions 0.3.4 to 0.3.5. The issue arises from a missing capability check in the wp_ajax_wpgm_start_geojson_import() function, allowing authenticated attackers with Subscriber-level access and above to elevate their privileges to that of an administrator.

Impact

Exploitation of this vulnerability allows authenticated users to gain administrative privileges, potentially leading to unauthorized changes or access within the WordPress site.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.9
remediation
0.0
relevance
0.1
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.