WP-GeoMeta Privilege Escalation Vulnerability in WordPress
Vulnerability
A privilege escalation vulnerability has been identified in the WP-GeoMeta plugin for WordPress, specifically in versions 0.3.4 to 0.3.5. The issue arises from a missing capability check in the wp_ajax_wpgm_start_geojson_import() function, allowing authenticated attackers with Subscriber-level access and above to elevate their privileges to that of an administrator.
Impact
Exploitation of this vulnerability allows authenticated users to gain administrative privileges, potentially leading to unauthorized changes or access within the WordPress site.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
5.0exploitability
5.9remediation
0.0relevance
0.1threat
3.2urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
