Aller au contenu

Fiche vulnérabilité

CVE-2023-5426 : faille élevée wpexpertplugins post meta data manager (CVSS 7.5)

Description

The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_delete_user_meta, pmdm_wp_delete_term_meta, and pmdm_wp_ajax_delete_meta functions in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to delete user, term, and post meta belonging to arbitrary users.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
28 oct. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • wpexpertplugins post meta data manager

Références

Rechercher une autre vulnérabilité dans la base CVE