SEO Metrics <= 1.0.15 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
highThe SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_connect_button_click() AJAX handler and the seo_metrics_handle_custom_endpoint() function in all versions up to, and including, 1.0.15. Because the AJAX action only verifies a no...
- CVSS:
- 8.8
- Affected:
- up to 1.0.15
- Fixed in:
- 1.0.16
- Disclosed:
- Aug 1, 2025