VYPR

Wp Geometa

by WordPress

Source repositories

CVEs (1)

  • CVE-2025-4103HigMay 31, 2025
    risk 0.57cvss 8.8epss 0.00

    The WP-GeoMeta plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wp_ajax_wpgm_start_geojson_import() function in versions 0.3.4 to 0.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above,…