CVE-2023-1026: WP Meta SEO <= 4.5.3 - Missing Authorization in 'listPostsCategory'
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the listPostsCategory function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to get post listings by category as long as those posts are published. This vulnerability occurred as a result of the plugin relying on nonce checks as a means of access control, and that nonce being accessible to all authenticated users regardless of role.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-1026?
CVE-2023-1026 is a vulnerability in the WP Meta SEO plugin for WordPress that allows unauthorized access to data.
What is the severity of CVE-2023-1026?
CVE-2023-1026 has a severity rating of medium with a value of 4.3.
How does CVE-2023-1026 affect the WP Meta SEO plugin?
CVE-2023-1026 affects versions of the WP Meta SEO plugin up to and including 4.5.3.
How can authenticated attackers exploit CVE-2023-1026?
Authenticated attackers with subscriber-level access can exploit CVE-2023-1026 to gain unauthorized access to post listings by category.
Is there a fix for CVE-2023-1026?
Yes, users should update their WP Meta SEO plugin to a version that includes the necessary capability check, such as version 4.5.4 or later.