PT-2026-95782 · WordPress · Metasync

·

CVE-2026-15947

·

Published

2026-09-19

·

Updated

2026-09-19

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Metasync versions prior to 2.6.24
Description The Metasync plugin for WordPress allows unauthorized modification of data because the save instant indexing settings() function lacks a capability check. The function is registered on the admin init hook and only verifies the presence of the submit parameter in the $ POST array before writing the metasync post types variable into the metasync options instant indexing site-wide option using update option(). Because no current user can() or current user has plugin access() checks and no nonce verification are performed, authenticated users with Subscriber-level access or higher can modify the Google Instant Indexing post-type configuration to control which post types are automatically submitted to Google's service.
Recommendations Update the plugin to a version newer than 2.6.23. As a temporary workaround, restrict access to the WordPress admin area for users with Subscriber-level permissions.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15947

Affected Products

Metasync