Medium severity5.4NVD Advisory· Published Feb 28, 2023· Updated Apr 8, 2026
CVE-2023-1023
CVE-2023-1023
Description
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the saveSitemapSettings function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to change sitemap-related settings of the plugin. This vulnerability occurred as a result of the plugin relying on nonce checks as a means of access control, and that nonce being accessible to all authenticated users regardless of role.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:joomunited:wp_meta_seo:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:joomunited:wp_meta_seo:*:*:*:*:*:wordpress:*:*range: <=4.5.3
- (no CPE)range: <=4.5.3
Patches
Vulnerability mechanics
References
4- plugins.trac.wordpress.org/changeset/2870465/wp-meta-seo/trunknvdPatch
- plugins.trac.wordpress.org/changesetnvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/9d1e498a-ddcb-4c67-bf0d-bb45b6fe0e9dnvdPatchThird Party Advisory
- www.wordfence.com/threat-intel/vulnerabilities/id/9d1e498a-ddcb-4c67-bf0d-bb45b6fe0e9dnvd
News mentions
0No linked articles in our index yet.