Access violation vulnerability in SiteSEO – SEO Simplified 1.3.2

The SiteSEO plugin for WordPress has a security issue that can allow unauthorized access to sensitive information in versions up to and including 1.3.2. This is because it does not have proper checks in place to control who can access certain post metadata through the custom field variable feature. This means that users with a certain level of access (such as Author-level users who have been given SiteSEO access by an administrator) can view private information from posts, pages, and orders, even if they are not able to edit them. In some cases, this can expose personal information from customers, such as their names, email addresses, phone numbers, addresses, and payment methods.

Detected in:

SiteSEO – SEO Simplified fixed vulnerable versions: >= * <= 1.3.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.