CVE-2023-0876: WP Meta SEO < 4.5.3 - Subscriber+ Improper Authorization causing Arbitrary Redirect
The WP Meta SEO WordPress plugin before 4.5.3 does not authorize several ajax actions, allowing low-privilege users to make updates to certain data and leading to an arbitrary redirect vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0876?
The severity of CVE-2023-0876 is medium with a CVSS score of 6.1.
What is the affected software of CVE-2023-0876?
The affected software of CVE-2023-0876 is the WP Meta SEO WordPress plugin before version 4.5.3.
What is the vulnerability description of CVE-2023-0876?
The vulnerability description of CVE-2023-0876 is that the WP Meta SEO WordPress plugin before 4.5.3 does not authorize several ajax actions, allowing low-privilege users to make updates to certain data and leading to an arbitrary redirect vulnerability.
How can the arbitrary redirect vulnerability be exploited in CVE-2023-0876?
The arbitrary redirect vulnerability in CVE-2023-0876 can be exploited by low-privilege users who are able to make unauthorized updates to certain data.
Is there a fix available for CVE-2023-0876?
Yes, the fix for CVE-2023-0876 is to update the WP Meta SEO WordPress plugin to version 4.5.3 or later.