CVE-2023-0876
WP Meta SEO < 4.5.3 - Subscriber+ Improper Authorization causing Arbitrary Redirect
Record summary
CVE-2023-0876 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The WP Meta SEO WordPress plugin before 4.5.3 does not authorize several ajax actions, allowing low-privilege users to make updates to certain data and leading to an arbitrary redirect vulnerability.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 24, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 26, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
WP Meta SEODefault status: unaffected | CVE List | Before 4.5.3 | affected |
wp_meta_seoBrowse joomunited / wp_meta_seo | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Meta SEO <= 4.5.2 - Open RedirectCVSS 6.1
The WP Meta SEO WordPress plugin before 4.5.3 did not authorize several AJAX actions, which allowed low-privilege users to update certain data and resulted in an arbitrary redirect vulnerability.
Impact
Authenticated attackers with low privileges can exploit unauthorized AJAX actions to update link redirects and create arbitrary redirect vulnerabilities that could be used for phishing attacks.
Remediation
Update the plugin to version 4.5.3 or later to fix the arbitrary redirect vulnerability.
Source: ProjectDiscovery