plugin

Post Meta Data Manager Vulnerabilities

13 known security issues reported for the Post Meta Data Manager WordPress plugin. Most recent disclosed Mar 8, 2025.

3 high 3 medium

Running Post Meta Data Manager on your site? Check whether your installed version is affected.

Scan your site free

Post Meta Data Manager [post-meta-data-manager] <= 1.4.3 (unfixed)

unknown

[en] The Post Meta Data Manager plugin for WordPress is vulnerable to multisite privilege escalation in all versions up to, and including, 1.4.3. This is due to the plugin not properly verifying the existence of a multisite installation prior to allowing user meta to be added/modified. This makes it possible for authen...

Affected:
up to 1.4.3
Fix:
No patched version reported
Disclosed:
Mar 8, 2025

CVE-2024-13835 on NVD →

Post Meta Data Manager <= 1.4.4 - Authentciated (Admin+) Multisite Privilege Escalation

high

The Post Meta Data Manager plugin for WordPress is vulnerable to multisite privilege escalation in all versions up to, and including, 1.4.4. This is due to the plugin not properly verifying the existence of a multisite installation prior to allowing user meta to be added/modified. This makes it possible for authenticat...

CVSS:
7.2
Affected:
up to 1.4.4
Fix:
No patched version reported
Disclosed:
Mar 7, 2025

CVE-2024-13835 on NVD →

Post Meta Data Manager [post-meta-data-manager] < 1.3.0

unknown

[en] The Post Meta Data Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$meta_key’ parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and ab...

Affected:
up to 1.3.0
Fixed in:
1.3.0
Disclosed:
Jul 2, 2024

CVE-2024-6264 on NVD →

Post Meta Data Manager <= 1.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Post Meta Data Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$meta_key’ parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,...

CVSS:
6.4
Affected:
up to 1.2.3
Fixed in:
1.3.0
Disclosed:
Jul 1, 2024

CVE-2024-6264 on NVD →

Post Meta Data Manager [post-meta-data-manager] < 1.2.2

unknown

[en] The Post Meta Data Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the pmdm_wp_ajax_delete_meta, pmdm_wp_delete_user_meta, and pmdm_wp_delete_user_meta functions. This makes it possible for unauthentica...

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Nov 21, 2023

CVE-2023-5776 on NVD →

Post Meta Data Manager <= 1.2.1 - Cross-Site Request Forgery to Post, Term, and User Meta Deletion

medium

The Post Meta Data Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the pmdm_wp_ajax_delete_meta, pmdm_wp_delete_user_meta, and pmdm_wp_delete_user_meta functions. This makes it possible for unauthenticated a...

CVSS:
4.3
Affected:
up to 1.2.1
Fixed in:
1.2.2
Disclosed:
Nov 20, 2023

CVE-2023-5776 on NVD →

Post Meta Data Manager [post-meta-data-manager] < 1.2.1

unknown

[en] The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_delete_user_meta, pmdm_wp_delete_term_meta, and pmdm_wp_ajax_delete_meta functions in versions up to, and including, 1.2.0. This makes it possible for unauthenticated...

Affected:
up to 1.2.1
Fixed in:
1.2.1
Disclosed:
Oct 28, 2023

CVE-2023-5426 on NVD →

Post Meta Data Manager [post-meta-data-manager] < 1.2.1

unknown

[en] The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_change_user_meta and pmdm_wp_change_post_meta functions in versions up to, and including, 1.2.0. This makes it possible for authenticated attackers, with subscriber-le...

Affected:
up to 1.2.1
Fixed in:
1.2.1
Disclosed:
Oct 28, 2023

CVE-2023-5425 on NVD →

Post Meta Data Manager <=1.2.0 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation

high

The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_change_user_meta and pmdm_wp_change_post_meta functions in versions up to, and including, 1.2.0. This makes it possible for authenticated attackers, with subscriber-level p...

CVSS:
8.8
Affected:
up to 1.2.0
Fixed in:
1.2.1
Disclosed:
Oct 27, 2023

CVE-2023-5425 on NVD →

Post Meta Data Manager <=1.2.0 - Missing Authorization to User, Term, and Post Meta Deletion

high

The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_delete_user_meta, pmdm_wp_delete_term_meta, and pmdm_wp_ajax_delete_meta functions in versions up to, and including, 1.2.0. This makes it possible for unauthenticated atta...

CVSS:
7.5
Affected:
up to 1.2.0
Fixed in:
1.2.1
Disclosed:
Oct 27, 2023

CVE-2023-5426 on NVD →

Post Meta Data Manager <= 1.2.0 - Missing Authorization to Post, Term, and User Meta Deletion

medium

The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification and loss of data due to missing capability checks on the pmdm_wp_ajax_delete_meta, pmdm_wp_delete_user_meta, and pmdm_wp_delete_user_meta functions hooked via nopriv AJAX actions in all versions up to, and including, 1.2.0. This...

CVSS:
5.3
Affected:
up to 1.2.0
Fixed in:
1.2.1
Disclosed:
Oct 20, 2023

Post Meta Data Manager [post-meta-data-manager] < 1.2.1

unknown

The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification and loss of data due to missing capability checks on the pmdm_wp_ajax_delete_meta, pmdm_wp_delete_user_meta, and pmdm_wp_delete_user_meta functions hooked via nopriv AJAX actions in all versions up to, and including, 1.2.0. This...

Affected:
up to 1.2.1
Fixed in:
1.2.1
Disclosed:
Oct 20, 2023

Post Meta Data Manager [post-meta-data-manager] < 1.2.1

unknown

The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification and loss of data due to missing capability checks on the pmdm_wp_ajax_delete_meta, pmdm_wp_delete_user_meta, and pmdm_wp_delete_user_meta functions hooked via nopriv AJAX actions in all versions up to, and including, 1.2.0. This...

Affected:
up to 1.2.1
Fixed in:
1.2.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database