Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 29 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lhughes33472
Lhughes33472 metamagic Seo Plugin Wordpress Wordpress wordpress |
|
| Vendors & Products |
Lhughes33472
Lhughes33472 metamagic Seo Plugin Wordpress Wordpress wordpress |
Wed, 27 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MetaMagic SEO Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing or incorrect nonce validation on the metamagic_update_options function. This makes it possible for unauthenticated attackers to modify the plugin's SEO settings, including enabling or disabling the plugin and toggling description and keyword meta tag output via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |
| Title | MetaMagic SEO Plugin <= 1.6 - Cross-Site Request Forgery to Plugin Settings Update via Settings Page | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-27T10:27:50.938Z
Reserved: 2026-05-19T12:08:49.981Z
Link: CVE-2026-8942
Updated: 2026-05-27T10:27:46.468Z
Status : Deferred
Published: 2026-05-27T08:16:45.787
Modified: 2026-06-17T11:04:38.360
Link: CVE-2026-8942
No data.
OpenCVE Enrichment
Updated: 2026-05-29T15:51:14Z