WordPress Plugin Vulnerabilities

WP Meta SEO < 4.5.3 - Subscriber+ Improper Authorization causing Arbitrary Redirect

Description

The plugin does not authorize several ajax actions, allowing low-privilege users to make updates to certain data and leading to an arbitrary redirect vulnerability.

Proof of Concept

Affects Plugins

Fixed in 4.5.3

References

Classification

Type
REDIRECT
OWASP top 10
CWE

Miscellaneous

Original Researcher
dc11
Submitter
dc11
Verified
Yes

Timeline

Publicly Published
2023-02-27 (about 2 years ago)
Added
2023-02-27 (about 2 years ago)
Last Updated
2023-02-27 (about 2 years ago)

Other