Impact
The flaw is a missing authorization check in the SEO Booster plugin for WordPress, classified as CWE-862. It permits users to access and potentially modify configuration settings or SEO data that they should not be able to reach, leading to undesired information disclosure or manipulation of the site’s search engine optimization.
Affected Systems
The vulnerability is present in the cleverplugins SEO Booster plugin versions from the beginning of its releases up through 6.1.8. No further version information is listed, so any installation using 6.1.8 or earlier is affected.
Risk and Exploitability
The CVSS score is 6.5, indicating a medium severity. The EPSS score is below 1%, suggesting a low current likelihood of exploitation, and the issue is not listed in the CISA KEV catalog. An attacker who can submit requests to the plugin’s endpoints—potentially via an authenticated WordPress session—can bypass authorization checks, making the attack vector likely to involve web request manipulation or administrative access credential theft.
OpenCVE Enrichment