Description
The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_connect_button_click() AJAX handler and the seo_metrics_handle_custom_endpoint() function in all versions up to, and including, 1.0.15. Because the AJAX action only verifies a nonce, without checking the caller’s capabilities, a subscriber-level user can retrieve the token and then access the custom endpoint to obtain full administrator cookies.
Problem types
Product status
Any version
Timeline
| 2025-08-01: | Disclosed |
Credits
Kenneth Dunn
References
www.wordfence.com/...-ae53-4919-8180-1188f72553f7?source=cve
wordpress.org/plugins/seo-metrics-helper/
plugins.trac.wordpress.org/...rics-helper/trunk/endpoint.php
plugins.trac.wordpress.org/...per/trunk/common-functions.php
plugins.trac.wordpress.org/...s-helper/trunk/seo-metrics.php
plugins.trac.wordpress.org/...-helper/trunk/welcome-page.php
plugins.trac.wordpress.org/...w=3343566%40seo-metrics-helper