Medium severity5.4NVD Advisory· Published Feb 28, 2023· Updated Apr 8, 2026
CVE-2023-1022
CVE-2023-1022
Description
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized options update due to a missing capability check on the wpmsGGSaveInformation function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to update google analytics options maintained by the plugin. This vulnerability occurred as a result of the plugin relying on nonce checks as a means of access control, and that nonce being accessible to all authenticated users regardless of role.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:joomunited:wp_meta_seo:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:joomunited:wp_meta_seo:*:*:*:*:*:wordpress:*:*range: <=4.5.3
- (no CPE)range: <=4.5.3
Patches
Vulnerability mechanics
References
4- plugins.trac.wordpress.org/changeset/2870465/wp-meta-seo/trunknvdPatchThird Party Advisory
- plugins.trac.wordpress.org/changesetnvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/702f9d3b-5d33-4215-ac76-9aae3162d775nvdPatchThird Party Advisory
- www.wordfence.com/threat-intel/vulnerabilities/id/702f9d3b-5d33-4215-ac76-9aae3162d775nvd
News mentions
0No linked articles in our index yet.