CVE-2022-30337
MEDIUMJoomUnited WP Meta SEO <= 4.4.8 - Cross-Site Request Forgery in Social Settings Update
Title source: llmDescription
Cross-Site Request Forgery (CSRF) vulnerability in JoomUnited WP Meta SEO plugin <= 4.4.8 at WordPress allows an attacker to update the social settings.
References (2)
Core 2
Core References
Patch, Third Party Advisory x_refsource_confirm
https://patchstack.com/database/vulnerability/wp-meta-seo/wordpress-wp-meta-seo-plugin-4-4-8-social-settings-update-vis-cross-site-request-forgery-csrf-vulnerability
Release Notes, Third Party Advisory x_refsource_confirm
https://wordpress.org/plugins/wp-meta-seo/#developers
Scores
CVSS v3
5.4
EPSS
0.0027
EPSS Percentile
19.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-352
Status
published
Products (2)
JoomUnited/WP Meta SEO (WordPress plugin)
<= 4.4.8 - 4.4.8
joomunited/wp_meta_seo
< 4.4.9
Published
Jul 21, 2022
Tracked Since
Feb 18, 2026