CVE-2026-15947
4.3 MEDIUMPublished 2026-09-19 · Updated 2026-09-21
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
The Metasync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_instant_indexing_settings() function in versions up to, and including, 2.6.23. This function is registered on the admin_init hook and only checks for the presence of $_POST['submit'] before writing attacker-supplied $_POST['metasync_post_types'] into the site-wide 'metasync_options_instant_indexing' option via update_option(); no current_user_can()/current_user_has_plugin_access() check and no nonce verification are performed. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the site's Google Instant Indexing post-type configuration, controlling which post types are auto-submitted to Google's Instant Indexing service.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weaknesses
CWE-862
All references
- https://plugins.trac.wordpress.org/browser/metasync/tags/2.6.16/admin/class-metasync-admin.php#L384
- https://plugins.trac.wordpress.org/browser/metasync/tags/2.6.16/admin/class-metasync-admin.php#L6358
- https://plugins.trac.wordpress.org/browser/metasync/tags/2.6.16/admin/class-metasync-admin.php#L6364
- https://plugins.trac.wordpress.org/browser/metasync/tags/2.6.17/admin/class-metasync-admin.php#L384
- https://plugins.trac.wordpress.org/browser/metasync/tags/2.6.17/admin/class-metasync-admin.php#L6358
- https://plugins.trac.wordpress.org/browser/metasync/tags/2.6.17/admin/class-metasync-admin.php#L6364
- https://plugins.trac.wordpress.org/changeset/3676919
- https://www.wordfence.com/threat-intel/vulnerabilities/id/1bfba54f-961d-4889-9272-0020c9fa0801?source=cve
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-14484
- MEDIUMCVE-2025-14486
- MEDIUMCVE-2025-14487
- MEDIUMCVE-2026-11899
- HIGHCVE-2026-12000
- UNSCOREDCVE-2026-13227PoC
- UNSCOREDCVE-2026-13229PoC
- MEDIUMCVE-2026-15946
Related by shared AI tags and CWE weakness class. Browse the full archive.