CVE-2026-49051

MEDIUM

WordPress WP Meta and Date Remover plugin <= 2.3.6 - Broken Access Control vulnerability

Title source: cna
STIX 2.1

Description

Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Meta and Date Remover: from n/a through 2.3.6.

Scores

CVSS v3 4.3
EPSS 0.0016
EPSS Percentile 5.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
Prasad Kirpekar/WP Meta and Date Remover < 2.3.6
Published May 27, 2026
Tracked Since May 27, 2026