CVE-2026-15947: Search Atlas SEO <= 2.6.23 - Missing Authorization to Authenticated (Subscriber+) Site-Wide Option Modification via 'metasync_post_types' Parameter

Published Sep 19, 2026
·
Updated

The Metasync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveinstantindexingsettings() function in versions up to, and including, 2.6.23. This function is registered on the admininit hook and only checks for the presence of $POST['submit'] before writing attacker-supplied $POST['metasyncposttypes'] into the site-wide 'metasyncoptionsinstantindexing' option via updateoption(); no currentusercan()/currentuserhaspluginaccess() check and no nonce verification are performed. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the site's Google Instant Indexing post-type configuration, controlling which post types are auto-submitted to Google's Instant Indexing service.

Affected Software

1 affected component
Metasync Metasync WordPress plugin<=2.6.23

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Metasync plugin for WordPress to a version that resolves this vulnerability.

    Fixed in 2.6.23

Event History

Sep 19, 2026
CVE Published
via MITRE·07:43 AM
Data Sourced
via MITRE·07:43 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated WordPress user with Subscriber-level access or higher can exploit it. No administrative capability is required.

2

What must an attacker be able to do to change the configuration?

The attacker needs a valid authenticated WordPress account and must submit a request containing the submit parameter and an attacker-controlled metasync_post_types value. The vulnerable handler does not require a capability check or nonce verification.

3

What can be changed through this vulnerability?

An attacker can alter the site-wide metasync_options_instant_indexing setting, specifically the post types configured for automatic submission to Google's Instant Indexing service. The provided information does not indicate that other plugin or WordPress settings can be modified through this issue.

4

Are default installations exposed?

The issue affects Metasync versions up to and including 2.6.23 because the vulnerable function runs on the admin_init hook. Exploitation still requires an authenticated account with at least Subscriber access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203