MEDIUM
shahrukhlinkgraph
CVE published 2026-09-19
CVE-2026-15947
The Metasync plugin for WordPress has a vulnerability allowing unauthorized modification of data due to a missing capability check on the save_instant_indexing_settings() function. This function, registered on the admin_init hook, writes attacker-supplied data into the site-wide 'metasync_options_instant_indexing' option without proper checks, allowing authenticated attackers with Subscriber-level access [truncated]