Impact
A missing authorization check in WPMU DEV’s SmartCrawl plugin allows an authenticated user to perform actions beyond their intended scope, effectively elevating privileges within the WordPress site. This broken access control flaw is identified by CWE‑862. The impact is the ability to modify SEO settings, potentially redirect traffic, alter metadata, or inject code that could lead to further compromise.
Affected Systems
The vulnerability affects the SmartCrawl SEO plugin from any version up to and including 3.14.3, as distributed by WPMU DEV as part of its All‑in‑One WordPress Platform. Owners of websites using SmartCrawl 3.14.3 or earlier should be aware that the flaw is present.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score of less than 1% suggests that exploitation is unlikely at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector would be a legitimate site user who gains access to the plugin’s administrative interface; the missing authorization allows that user to perform actions normally restricted to higher‑privileged roles. No public exploit has been identified, but the flaw could be leveraged to undermine site integrity if an attacker gains authenticated access.
OpenCVE Enrichment