Severity
4.3MEDIUMNVD
EPSS
0.2%
top 60.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 28
Latest updateDec 30

Description

The WP Meta SEO plugin for WordPress is vulnerable to unauthorized sitemap generation due to a missing capability check on the regenerateSitemaps function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to generate sitemaps. This vulnerability occurred as a result of the plugin relying on nonce checks as a means of access control, and that nonce being accessible to all authenticated users regardless of role.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

Patches

🔴Vulnerability Details

5
OSV
bpf: Silence a warning in btf_type_id_size()2025-12-30
GHSA
Withdrawn Advisory: Access control issues in blackbox_exporter2023-04-26
CVEList
WP Meta SEO <= 4.5.3 - Missing Authorization in 'regenerateSitemaps'2023-02-28
GHSA
GHSA-rqjh-2xp3-wp52: The WP Meta SEO plugin for WordPress is vulnerable to unauthorized sitemap generation due to a missing capability check on the regenerateSitemaps func2023-02-28
GHSA
IPFS go-unixfsnode subject to DOS via HAMT Decoding Panics2023-02-10

💥Exploits & PoCs

1
Nuclei
glibc's syslog - Local Privilege Escalation

📋Vendor Advisories

8
Red Hat
kernel: bpf: Silence a warning in btf_type_id_size()2025-12-30
Red Hat
kernel: Linux kernel: BPF verifier log truncation via crafted user input2025-12-24
Red Hat
kernel: scsi: qla2xxx: Fix DMA-API call trace on NVMe LS requests2025-12-24
Red Hat
kernel: fs/ntfs3: Fix null-ptr-deref on inode->i_op in ntfs_lookup()2025-09-16
Red Hat
kernel: coresight: Fix memory leak in acpi_buffer->pointer2025-09-15
CVE-2023-1024 — Missing Authorization in WP Meta SEO | cvebase