CVE-2023-1381: Joomunited Wp Meta Seo
High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.
The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR deserialization vulnerability. Furthermore, the plugin contains a gadget chain which may be used in certain configurations to achieve remote code execution.
Affected products
- Joomunited Wp Meta Seo: before 4.5.5 (fixed in 4.5.5)
Published 2023-04-10. Last modified 2026-06-17.