4.3
CVSSv3

CVE-2023-1027

Published: 28/02/2023 Updated: 07/11/2023
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The WP Meta SEO plugin for WordPress is vulnerable to unauthorized sitemap generation due to a missing capability check on the checkAllCategoryInSitemap function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to obtain post categories. This vulnerability occurred as a result of the plugin relying on nonce checks as a means of access control, and that nonce being accessible to all authenticated users regardless of role.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

joomunited wp meta seo

Github Repositories

Offline API for GSD

CVE-Land I'm working on a side project In my use case, I needed to have a sort of API interface with some vuln data without performing tons of queries on external third-party services I have a lot of work ahead of me, as I'm planning on adding things and making improvements The API now uses mongodb as I am making a mini production instance on my network for this pr