GZSEO
GZSEO has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2026; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 5.8, and the most serious one scores 6.4 out of 10. 2026 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Missing Authorization.
1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.
2 independent researchers contributed these findings, one record each. GZSEO is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2026-25437GZSEO <= 2.0.14 - Missing Authorization
Read the full analysisVulnerability Records

GZSEO is a powerful SEO assistant plugin that offers incredible features. With this plugin, you can easily identify underperforming keywords and update content powered by ChatGPT Terms & Conditions You can find detailed information regarding the terms and conditions for using the GZSEO plugin at the following link: https://gzseo.in/terms/ Privacy & Policy Your privacy and security are always our top priority. You can review all details about this topic at the following link: https://gzseo.in/privacy-policy/ External Services https://gzseo.in To retrieve Google Search Console queries, a confirmation request is sent to gzseo.in. No data is stored on this site; it only acts as an intermediary between your site and Google Search Console. For more details, please review our Terms and Conditions and Privacy Policy pages. Terms & Conditions: https://gzseo.in/terms/ Privacy Policy: https://gzseo.in/privacy-policy/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C