Impact
The SEO Booster plugin for WordPress contains a missing authorization check in the handle_oauth_callback() function. This callback, triggered on admin initialization, processes the $_GET['access_token'] and $_GET['google_email'] parameters without verifying the caller’s role. Consequently, an authenticated user with Subscriber-level access or higher can craft a request to a /wp-admin/ URL and overwrite the seobooster_access_token, seobooster_google_email, seobooster_gsc_sites options and delete the seobooster_needs_reauth flag. The effect is that an attacker can inject malicious data into site options, disrupt the Google Search Console integration, and potentially influence outbound Google API requests based on a tampered token.
Affected Systems
Cleverplugins SEO Booster for WordPress, versions up to and including 7.4.7. All installations running any of these versions are directly affected due to the lack of a capability check in the OAuth callback handler.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score is not available; therefore the likelihood of exploitation cannot be precisely quantified but is not ruled out. The vulnerability is not listed in the CISA KEV catalog. An attacker only requires authenticated access with Subscriber privileges, which is relatively common, suggesting a potentially wide surface of compromise for sites with higher‑privileged users.
OpenCVE Enrichment