Impact
The WordPress SEO Meta Description Updater plugin suffers from a missing authorization flaw that allows attackers to bypass incorrectly configured access control security levels. This vulnerability enables an attacker to modify the plugin’s meta‑description settings and potentially extend changes to other areas of the WordPress installation, compromising the integrity of the site’s metadata and, if the plugin is used for marketing or SEO, the overall content presented to visitors.
Affected Systems
The affected component is the SEO Meta Description Updater plugin developed by Joby Joseph. It is vulnerable in all releases from the initial version through and including 1.2.0. No other versions are listed as affected.
Risk and Exploitability
With a CVSS score of 4.3, the severity is moderate. The EPSS score of less than 1% indicates a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Attackers would most likely exploit the flaw through the WordPress web interface, targeting the plugin’s admin pages where the access control checks are insufficient. Although the risk is currently low, the potential for unauthorized changes to critical metadata warrants prompt attention.
OpenCVE Enrichment