CVE-2023-0876

MEDIUM EXPLOITED NUCLEI

WP Meta SEO < 4.5.3 - Unauthenticated Arbitrary Redirect via Unauthorized AJAX Actions

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-0876 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.

Description

The WP Meta SEO WordPress plugin before 4.5.3 does not authorize several ajax actions, allowing low-privilege users to make updates to certain data and leading to an arbitrary redirect vulnerability.

Nuclei Templates (1)

WordPress Meta SEO <= 4.5.2 - Open Redirect
MEDIUMVERIFIEDby Khalid6468
FOFA: body="/wp-content/plugins/wp-meta-seo/"

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/1a8c97f9-98fa-4e29-b7f7-bb9abe0c42ea

Scores

CVSS v3 6.1
EPSS 0.0071
EPSS Percentile 48.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

VulnCheck KEV 2023-02-24
Status published
Products (1)
joomunited/wp_meta_seo < 4.5.3
Published Mar 20, 2023
Tracked Since Feb 18, 2026