Impact
A missing authorization check in the WordPress GZSEO plugin up to version 2.0.14 allows users without proper credentials to perform actions that should be restricted. This flaw, classified as CWE‑862, enables unintended access to plugin functions and potentially exposed data or administrative actions."
Affected Systems
The vulnerability applies to all releases of the GZSEO plugin produced by سید محمدامین هاشمی from the earliest documented version up to and including 2.0.14. Sites that have any of these versions installed are at risk if the plugin is active.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity assessment, while the EPSS score of less than 1 % reflects a low likelihood of widespread exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploits. Based on the description, the likely attack vector is via the WordPress web interface where the plugin’s access checks are omitted; an attacker would need to craft HTTP requests targeting the plugin’s endpoints to gain unauthorized access.
OpenCVE Enrichment