PT-2025-31725 · WordPress · Seo Metrics

Kenneth Dunn

·

Published

2025-08-02

·

Updated

2025-08-07

·

CVE-2025-6754

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SEO Metrics versions 1.0.5 through 1.0.15
Description The SEO Metrics plugin for WordPress is susceptible to privilege escalation due to insufficient authorization checks. Specifically, the seo metrics handle connect button click() AJAX handler and the seo metrics handle custom endpoint() function lack proper capability verification. A subscriber-level user can obtain a token and access the custom endpoint, potentially gaining full administrator cookies.
Recommendations Versions prior to 1.0.5 are not affected. Update to a version later than 1.0.15.

Fix

LPE

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-6754

Affected Products

Seo Metrics