PT-2023-16701 · WordPress · Wp Meta Seo
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WP Meta SEO plugin for WordPress versions up to and including 4.5.3
Description
The issue is related to Cross-Site Request Forgery due to missing or incorrect nonce validation on the
regenerateSitemaps function. This allows unauthenticated attackers to regenerate Sitemaps via a forged request if they can trick a site administrator into performing a specific action, such as clicking on a link.Recommendations
For WP Meta SEO plugin for WordPress versions up to and including 4.5.3, update to a version that includes the fix for the nonce validation issue in the
regenerateSitemaps function. As a temporary workaround, consider restricting access to the regenerateSitemaps function to prevent unauthenticated attackers from regenerating Sitemaps.Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wp Meta Seo