CVE-2025-49376
7.5DELUCKS · DELUCKS SEO
A missing authorization vulnerability in the DELUCKS SEO WordPress plugin allows unauthenticated attackers to access restricted plugin functionality.
Executive summary
The DELUCKS SEO plugin is susceptible to a missing authorization vulnerability that enables unauthenticated access to restricted plugin functions, posing a risk of unauthorized configuration changes.
Vulnerability
This vulnerability is categorized as a missing authorization flaw (CWE-862) within the delucks-seo plugin. The vulnerability permits an unauthenticated attacker to interact with plugin functions that lack proper access control checks.
Business impact
The ability for unauthenticated users to interact with plugin functionality can lead to unauthorized modifications of SEO settings or other plugin-managed configurations. With a CVSS score of 7.5, this high-severity vulnerability warrants immediate attention to prevent potential service integrity loss or unauthorized manipulation of site content.
Remediation
Immediate Action: Since a specific patch version is not currently identified in the provided data, users are advised to monitor the vendor repository or deactivate the plugin until a secure update is released.
Proactive Monitoring: Security teams should review server access logs for anomalous requests directed at plugin-specific endpoints or unauthorized configuration changes.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized access to the plugin's administrative or functional endpoints.
Exploitation status
Public Exploit Available: No (exploit_available: false).
Analyst recommendation
Given the high-severity rating and the lack of authentication required to trigger the flaw, administrators must prioritize identifying if this plugin is present in their environment. If the plugin is in use, verify if a secure version has been released by the vendor and apply it immediately, or consider removing the component to eliminate the attack surface entirely.
More DELUCKS CVEs
Sources
Originally found and disclosed by ch4r0n | Patchstack Bug Bounty Program, per the CVE Program record.