CVE-2023-0876

MEDIUM EXPLOITED NUCLEI

WP Meta SEO <4.5.3 - CSRF

Title source: llm

Description

The WP Meta SEO WordPress plugin before 4.5.3 does not authorize several ajax actions, allowing low-privilege users to make updates to certain data and leading to an arbitrary redirect vulnerability.

Nuclei Templates (1)

WordPress Meta SEO <= 4.5.2 - Open Redirect
MEDIUMVERIFIEDby Khalid6468
FOFA: body="/wp-content/plugins/wp-meta-seo/"

Scores

CVSS v3 6.1
EPSS 0.0230
EPSS Percentile 84.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

VulnCheck KEV 2023-02-24
Status published
Products (1)
joomunited/wp_meta_seo < 4.5.3
Published Mar 20, 2023
Tracked Since Feb 18, 2026