The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.
References
Link | Resource |
---|---|
https://rankmath.com/changelog/ | Product Release Notes |
https://www.wordfence.com/blog/2020/03/critical-vulnerabilities-affecting-over-200000-sites-patched-in-rank-math-seo-plugin/ | Exploit Third Party Advisory |
https://wordpress.org/plugins/seo-by-rank-math/#developers | Product |
Configurations
Information
Published : 2020-04-07 10:15
Updated : 2021-07-21 04:39
NVD link : CVE-2020-11514
Mitre link : CVE-2020-11514
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
rankmath
- rankmath