CVE-2023-5426
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Oct 28, 2023
Updated: Nov 8, 2023
Summary
CVE-2023-5426 is a vulnerability affecting the Post Meta Data Manager plugin for WordPress. The issue arises from the absence of capability checks on the functions pmdm_wp_delete_user_meta, pmdm_wp_delete_term_meta, and pmdm_wp_ajax_delete_meta, present in versions up to 1.2.0. Consequently, unauthenticated attackers can manipulate and delete user, term, and post meta information for arbitrary users on a WordPress site, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share