Unauthorized Settings Modification in WP Meta SEO Plugin for WordPress
CVE-2023-1023
What is CVE-2023-1023?
The WP Meta SEO plugin for WordPress is susceptible to an authorization bypass flaw that allows authenticated users with subscriber-level access to manipulate the plugin's sitemap settings. This vulnerability arises from the absence of a proper capability check in the saveSitemapSettings function, leading to reliance on nonce validation that is accessible to all authenticated users, irrespective of their roles. Consequently, this oversight permits potential exploitation where attackers can alter vital plugin configurations without adequate permission.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Meta SEO * <= 4.5.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved