Junglewise Threat Intelligence

CVE-2026-49051: Prasad Kirpekar WP Meta and Date Remover missing authorization

CVE-2026-49051 · Severity: medium · CVSS 4.3 · Published 2026-05-27

Executive brief

WP Meta and Date Remover is a WordPress plugin used to hide metadata like author names and publication dates from website posts. A security flaw in the plugin allows logged-in users with low-level permissions, such as subscribers, to bypass security checks and access or modify settings they should not be able to reach. This could lead to unauthorized changes to how site content is displayed or the exposure of internal configuration details.

Technical details

A missing authorization vulnerability (CWE-862) exists in the WP Meta and Date Remover plugin for WordPress through version 2.3.6. The flaw stems from insufficient access control checks on plugin functions, allowing an authenticated attacker with minimal privileges (Subscriber level) to execute actions or access data intended for higher-privileged users. The attack is reachable over the network without user interaction. As of the advisory date, no official patch has been released, and users are advised to monitor for updates or restrict access to the plugin's administrative functions.

Affected products

  • Prasad Kirpekar WP Meta and Date Remover n/a through 2.3.6

Timeline

  • 2026-02-03: other: Reported by Trương Hữu Phúc
  • 2026-05-27: advisory: Published by Patchstack and NVD

References