CVE-2026-25437
WordPress GZSEO plugin <= 2.0.14 - Broken Access Control vulnerability
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
4th
Missing Authorization vulnerability in سید محمدامین هاشمی GZSEO gzseo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GZSEO: from n/a through <= 2.0.14.
| CWE | CWE-862 |
| Vendor | سید محمدامین هاشمی |
| Product | gzseo |
| Published | Mar 25, 2026 |
| Last Updated | Mar 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for سید محمدامین هاشمی gzseo
Be the first to know when new medium vulnerabilities affecting سید محمدامین هاشمی gzseo are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
سید محمدامین هاشمی / GZSEO
n/a ≤ <= 2.0.14
References
Credits
Legion Hunter | Patchstack Bug Bounty Program