SEO Plugin by Squirrly SEO < 6.1.5 - Missing Authorization Checks

2016-07-11 00:00
Panagiotis Vagenas

Strategic Overview

Status
Patched in 6.1.5
Affected Version< 6.1.5
CVSS7.3High
CVEN/A
View all GEO Plugin by Squirrly SEO vulnerabilities

Vulnerability Overview

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to authorization bypass in versions before 6.1.5. This makes it possible for authenticated attackers to modify plugin settings on a site with registration enabled. This includes adding or changing the site favicon, uploading featured images for posts or retrieving SEO settings for a post.

Technical Analysis

REMEDIATION: Update to version 6.1.5, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C