CVE-2026-49051
Description
Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WP Meta and Date Remover: from n/a through 2.3.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in WP Meta and Date Remover plugin up to 2.3.6 allows unauthenticated attackers to exploit broken access controls, potentially leading to unauthorized data manipulation.
Vulnerability
The WP Meta and Date Remover plugin for WordPress, versions up to 2.3.6, contains a missing authorization vulnerability [1]. This broken access control issue allows attackers to exploit incorrectly configured access control security levels. The plugin fails to properly verify permissions or nonce tokens on certain functions, making them accessible without authentication.
Exploitation
An attacker can exploit this vulnerability remotely without any authentication or user interaction [1]. By sending crafted HTTP requests to the vulnerable endpoints, the attacker can trigger the missing authorization flaw. No special network position or prior access is required.
Impact
Successful exploitation enables an attacker to perform actions that should be restricted to higher-privileged users, such as modifying or removing post meta and dates [1]. This could lead to unauthorized data manipulation, site defacement, or other integrity impacts. The vulnerability is known to be used in mass-exploit campaigns.
Mitigation
As of the publication date, no patched version of the plugin has been released [1]. Users should update to a fixed version as soon as it becomes available. If unable to update, consider disabling the plugin or implementing additional access controls. The vulnerability is tracked in the Patchstack database.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<=2.3.6+ 1 more
- (no CPE)range: <=2.3.6
- (no CPE)range: <=2.3.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.