Record summary

CVE-2023-0876 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The WP Meta SEO WordPress plugin before 4.5.3 does not authorize several ajax actions, allowing low-privilege users to make updates to certain data and leading to an arbitrary redirect vulnerability.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 24, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 26, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

WP Meta SEO

Default status: unaffected

CVE ListBefore 4.5.3affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Meta SEO <= 4.5.2 - Open RedirectCVSS 6.1

The WP Meta SEO WordPress plugin before 4.5.3 did not authorize several AJAX actions, which allowed low-privilege users to update certain data and resulted in an arbitrary redirect vulnerability.

Impact

Authenticated attackers with low privileges can exploit unauthorized AJAX actions to update link redirects and create arbitrary redirect vulnerabilities that could be used for phishing attacks.

Remediation

Update the plugin to version 4.5.3 or later to fix the arbitrary redirect vulnerability.

WeaknessesCWE-601
AuthorsKhalid6468
Template tagswpscancvecve2023wpwp-pluginwordpresswp-meta-seoredirectvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:joomunited:wp_meta_seo:*:*:*:*:*:wordpress:*:*
FOFA: body="/wp-content/plugins/wp-meta-seo/"

Source: ProjectDiscovery

References

2