CVE-2025-12367
The SiteSEO – SEO Simplified WordPress plugin has a security flaw in versions 1.3.1 and earlier, which allows unauthorized users with at least Author-level permissions to manipulate settings for certain features without proper clearance. This occurs because the plugin fails to adequately check user authorization before allowing access to these settings. As a result, attackers can exploit this vulnerability to alter SiteSEO configurations beyond their intended scope.
Based on public CVE data (MITRE/NVD).