MetaMagic SEO Plugin
- <= 1.6
A Cross-Site Request Forgery (CSRF) vulnerability exists in the MetaMagic SEO Plugin for WordPress, affecting all versions through 1.6. The issue arises from inadequate nonce validation in the 'metamagic_update_options' function, allowing unauthenticated attackers to alter the plugin's SEO settings. This includes enabling or disabling the plugin and modifying the output of description and keyword meta tags. Exploitation requires tricking a site administrator into clicking a link that initiates the forged request.
Exploitation of this vulnerability allows for unauthorized modification of the plugin's SEO settings, potentially disrupting a site's search engine optimization strategy and how the site is presented in search results.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.