What the vulnerability does
01Description
Missing Authorization vulnerability in prasadkirpekar WP Meta and Date Remover wp-meta-and-date-remover allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Meta and Date Remover: from n/a through <= 2.3.0.
Explanation of Vulnerability in Simple Terms
02Summary
WP Meta and Date Remover through version 2.3.0 fails to properly check user permissions before allowing modifications to post metadata and dates. An authenticated user with low privileges can alter or delete metadata and change publication dates on posts they should not have access to modify. This affects the integrity of post data across the site.
What an attacker can do
03Attacker Capabilities
Modify or delete post metadata and change publication dates on posts without proper authorization.
Potential impact on your site
04Site Impact
Post metadata and publication dates can be altered by users who should not have that capability, compromising content integrity.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege authenticated account (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
December 9, 2024
CVE published
April 29, 2026
Record updated