CVE · Medium

CVE-2025-12367 — SiteSEO – SEO Simplified [siteseo] < 1.3.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-12367 SiteSEO – SEO Simplified [siteseo] < 1.3.2 Improper Authorization Medium 4.3 < 1.3.2 1.3.2 2025-10-31

CVE-2025-12367

The SiteSEO – SEO Simplified WordPress plugin has a security flaw in versions 1.3.1 and earlier, which allows unauthorized users with at least Author-level permissions to manipulate settings for certain features without proper clearance. This occurs because the plugin fails to adequately check user authorization before allowing access to these settings. As a result, attackers can exploit this vulnerability to alter SiteSEO configurations beyond their intended scope.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.