Impact
The Metasync plugin for WordPress is vulnerable because the save_instant_indexing_settings() function, registered on the admin_init hook, eliminates any capability check before writing user‑supplied POST data to the 'metasync_options_instant_indexing' site option; the only guard is a check for the presence of $_POST['submit']. No current_user_can() or nonce verification is performed. This flaw allows any authenticated user with Subscriber‑level access or higher to alter the Google Instant Indexing post‑type configuration, controlling which post types are automatically submitted to Google. The primary impact is uncontrolled modification of a site‑wide configuration that could affect search visibility and content disclosure.
Affected Systems
All releases of Search Atlas SEO – OTTO AI SEO Automation for WordPress up to and including version 2.6.23 are affected. The vulnerability resides in the save_instant_indexing_settings() routine found in the plugin's admin class. Site administrators should verify the installed plugin version and upgrade if the running version is 2.6.23 or earlier.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. Because the flaw is accessed through normal WordPress admin POST requests and does not require a CSRF token, an attacker can craft a simple authenticated request to the plugin's options page. The vulnerability is not listed in the CISA KEV catalog, and no public exploit has been reported. Nevertheless, because any user with Subscriber‑level or higher can change the indexing configuration, the risk is significant for organizations that rely on precise search engine submission rules.
OpenCVE Enrichment