Impact
A missing authorization check in the Meta Tag Manager plugin allows anyone with network access to a WordPress site to alter meta tags without proper authentication. The vulnerability is classified as CWE‑862, Broken Access Control. The attacker can modify the meta information that WordPress outputs, potentially changing site behavior or search engine metadata. No evidence of remote code execution or direct injection is provided in the description, so the impact is confined to unauthorized configuration changes.
Affected Systems
WordPress installations that have installed any version of the Meta Tag Manager plugin from the earliest release through version 3.1 are affected. All users who have installed or are using those plugin versions on their site are potentially impacted.
Risk and Exploitability
The vulnerability carries a CVSS score of 4.3, indicating moderate severity. An EPSS score of less than 1 % suggests the likelihood of exploitation in the wild is very low, and the vulnerability is not listed in the CISA KEV catalog, so there is no known public exploitation. An attacker would need access to the WordPress site and would interact with the plugin’s endpoints without encountering an authentication check, allowing unauthorized changes to meta‑tag settings.
OpenCVE Enrichment
EUVD