The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.
References
| Link | Resource |
|---|---|
| https://rankmath.com/changelog/ | Product Release Notes |
| https://www.wordfence.com/blog/2020/03/critical-vulnerabilities-affecting-over-200000-sites-patched-in-rank-math-seo-plugin/ | Exploit Third Party Advisory |
| https://wordpress.org/plugins/seo-by-rank-math/#developers | Product |
Configurations
Information
Published : 2020-04-07 17:15
Updated : 2021-07-21 11:39
NVD link : CVE-2020-11514
Mitre link : CVE-2020-11514
JSON object : View
Products Affected
rankmath
- rankmath
CWE
CWE-269
Improper Privilege Management
