The WP Meta SEO WordPress plugin before 4.5.3 did not authorize several AJAX actions, which allowed low-privilege users to update certain data and resulted in an arbitrary redirect vulnerability.
id: CVE-2023-0876
info:
name: WordPress Meta SEO <= 4.5.2 - Open Redirect
author: Khalid6468
...