VYPR

Wp Meta And Date Remover

by Prasadkirpekar

CVEs (2)

  • CVE-2023-4823MedOct 31, 2023
    risk 0.35cvss 5.4epss 0.00

    The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings. This endpoint has no capability checks and does not sanitize the user input, which is then later output unescaped. Allowing any authenticated users, such as…

  • CVE-2026-49051MedMay 27, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Meta and Date Remover: from n/a through 2.3.6.