---
id: CVE-2026-15947
title: >-
  The Metasync plugin for WordPress is vulnerable to unauthorized modification
  of data due to a missing capability check on the
  save_instant_indexing_settings() function in versions up to, and including,
  2.6.23
summary: >-
  The Metasync plugin for WordPress is vulnerable to unauthorized modification
  of data due to a missing capability check on the
  save_instant_indexing_settings() function in versions up to, and including,
  2.6.23. This function is registered…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
vendor: shahrukhlinkgraph
product: Search Atlas SEO – OTTO AI SEO Automation for WordPress
affected:
  - search_atlas_seo_otto_ai_seo_automation_for_wordpress <= 2.6.23
published: '2026-09-19'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T13:33:33.387'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15947'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/metasync/tags/2.6.16/admin/class-metasync-admin.php#L384
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/metasync/tags/2.6.16/admin/class-metasync-admin.php#L6358
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/metasync/tags/2.6.16/admin/class-metasync-admin.php#L6364
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/metasync/tags/2.6.17/admin/class-metasync-admin.php#L384
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/metasync/tags/2.6.17/admin/class-metasync-admin.php#L6358
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/metasync/tags/2.6.17/admin/class-metasync-admin.php#L6364
    label: security@wordfence.com
  - url: 'https://plugins.trac.wordpress.org/changeset/3676919'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/1bfba54f-961d-4889-9272-0020c9fa0801?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
epss: 0.00213
epssPercentile: 0.11951
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-19T13:24:40.330847Z'
ingestedAt: '2026-09-19T07:59:56.114Z'
---

## Overview

The Metasync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_instant_indexing_settings() function in versions up to, and including, 2.6.23. This function is registered on the admin_init hook and only checks for the presence of $_POST['submit'] before writing attacker-supplied $_POST['metasync_post_types'] into the site-wide 'metasync_options_instant_indexing' option via update_option(); no current_user_can()/current_user_has_plugin_access() check and no nonce verification are performed. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the site's Google Instant Indexing post-type configuration, controlling which post types are auto-submitted to Google's Instant Indexing service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
