CVE-2023-1027: WP Meta SEO <= 4.5.3 - Missing Authorization in 'checkAllCategoryInSitemap'
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized sitemap generation due to a missing capability check on the checkAllCategoryInSitemap function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to obtain post categories. This vulnerability occurred as a result of the plugin relying on nonce checks as a means of access control, and that nonce being accessible to all authenticated users regardless of role.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-1027?
CVE-2023-1027 is a vulnerability in the WP Meta SEO plugin for WordPress that allows unauthorized sitemap generation.
What is the severity of CVE-2023-1027?
The severity of CVE-2023-1027 is medium with a severity value of 4.3.
How does CVE-2023-1027 affect the WP Meta SEO plugin?
CVE-2023-1027 affects WP Meta SEO plugin versions up to, and including, 4.5.3.
How can an attacker exploit CVE-2023-1027?
An authenticated attacker with subscriber-level access can exploit CVE-2023-1027 to obtain post categories that they are not authorized to access.
Is there a fix for CVE-2023-1027?
Yes, updating the WP Meta SEO plugin to version 4.5.4 or later will fix the vulnerability.