← back to popular plugins
wordfence / plugin · meta-tag-manager

Meta Tag Manager

meta-tag-manager
total installs
80,000
total vulns
2
critical
0
high
0
medium
2
low
0
latest vuln
patched
2
unpatched
0
avg time to patch
vulnerabilities (2)
Meta Tag Manager <= 3.2 - Open Redirect
medium ✓ patched
cvss score 4.7
cwe CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
published Oct 1, 2025
The Meta Tag Manager plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.2. This is due to insufficient validation on the redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.
Meta Tag Manager <= 3.1 - Missing Authorization
medium ✓ patched
cvss score 4.3
cwe CWE-862: Missing Authorization
published Jan 31, 2025
The Meta Tag Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.