Medium severity4.3NVD Advisory· Published Feb 28, 2023· Updated Apr 8, 2026
CVE-2023-1026
CVE-2023-1026
Description
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the listPostsCategory function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to get post listings by category as long as those posts are published. This vulnerability occurred as a result of the plugin relying on nonce checks as a means of access control, and that nonce being accessible to all authenticated users regardless of role.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:joomunited:wp_meta_seo:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:joomunited:wp_meta_seo:*:*:*:*:*:wordpress:*:*range: <=4.5.3
- (no CPE)range: <=4.5.3
Patches
Vulnerability mechanics
References
4- plugins.trac.wordpress.org/changesetnvdPatch
- plugins.trac.wordpress.org/changeset/2870465/wp-meta-seo/trunknvdThird Party Advisory
- www.wordfence.com/threat-intel/vulnerabilities/id/978d5715-7993-4f89-8d69-895467633bfbnvdBroken Link
- www.wordfence.com/threat-intel/vulnerabilities/id/978d5715-7993-4f89-8d69-895467633bfbnvd
News mentions
0No linked articles in our index yet.