PT-2026-95782 · WordPress · Metasync
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Metasync versions prior to 2.6.24
Description
The Metasync plugin for WordPress allows unauthorized modification of data because the
save instant indexing settings() function lacks a capability check. The function is registered on the admin init hook and only verifies the presence of the submit parameter in the $ POST array before writing the metasync post types variable into the metasync options instant indexing site-wide option using update option(). Because no current user can() or current user has plugin access() checks and no nonce verification are performed, authenticated users with Subscriber-level access or higher can modify the Google Instant Indexing post-type configuration to control which post types are automatically submitted to Google's service.Recommendations
Update the plugin to a version newer than 2.6.23.
As a temporary workaround, restrict access to the WordPress admin area for users with Subscriber-level permissions.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Metasync