CVE-2023-1381: WP Meta SEO < 4.5.5 - Author+ PHAR Deserialization
The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR deserialization vulnerability. Furthermore, the plugin contains a gadget chain which may be used in certain configurations to achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-1381.
What is the title of this vulnerability?
The title of this vulnerability is 'The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR deserialization vulnerability.'
What is the severity of CVE-2023-1381?
The severity of CVE-2023-1381 is high with a CVSS score of 8.8.
What software is affected by CVE-2023-1381?
The WP Meta SEO WordPress plugin versions up to 4.5.5 are affected by CVE-2023-1381.
How can the vulnerability in the WP Meta SEO WordPress plugin be fixed?
To fix the vulnerability in the WP Meta SEO WordPress plugin, update it to version 4.5.5 or later.