Executive brief
The MetaMagic SEO Plugin for WordPress, which helps manage website search engine optimization settings, is vulnerable to a security flaw that allows unauthorized changes. By tricking a site administrator into clicking a malicious link, an attacker can remotely modify the plugin's settings, such as disabling SEO features or changing meta tags. This could negatively impact a website's search engine ranking and visibility.
Technical details
The MetaMagic SEO Plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the 'metamagic_update_options' function. This vulnerability affects all versions up to and including 1.6. An unauthenticated attacker can exploit this by inducing a site administrator to perform an action, such as clicking a link, which triggers a forged request to the vulnerable site. Successful exploitation allows the attacker to modify the plugin's SEO settings, including enabling or disabling the plugin and toggling description and keyword meta tag output. This is a client-side attack requiring user interaction from an authenticated administrator.
Affected products
- MetaMagic MetaMagic SEO Plugin up to, and including, 1.6
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory