🔙 목록으로 돌아가기

CVE-2023-0876: WordPress Meta SEO <= 4.5.2 - Open Redirect

TitleWordPress Meta SEO <= 4.5.2 - Open Redirect
AuthorKhalid6468
SeverityMedium
ImpactAuthenticated attackers with low privileges can exploit unauthorized AJAX actions to update link redirects and create arbitrary redirect vulnerabilities that could be used for phishing attacks.
RemediationUpdate the plugin to version 4.5.3 or later to fix the arbitrary redirect vulnerability.
CVSS Score6.1
EPSS Score0.09476
CVE IDCVE-2023-0876
CWE IDCWE-601
Fofa Querybody="/wp-content/plugins/wp-meta-seo/"
Tags wpscan cve cve2023 wp wp-plugin wordpress wp-meta-seo redirect vkev vuln

🔍 Vulnerability Description

The WP Meta SEO WordPress plugin before 4.5.3 did not authorize several AJAX actions, which allowed low-privilege users to update certain data and resulted in an arbitrary redirect vulnerability.

🌐 HTTP Request

GET /wp-content/plugins/wp-meta-seo/readme.txt HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.127 Safari/537.36
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-0876.yaml

🦈 Packet Capture: ⬇️ Download cve-2023-0876.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A