The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.
References
Link | Resource |
---|---|
https://rankmath.com/changelog/ | Product Release Notes |
https://wordpress.org/plugins/seo-by-rank-math/#developers | Product |
https://www.wordfence.com/blog/2020/03/critical-vulnerabilities-affecting-over-200000-sites-patched-in-rank-math-seo-plugin/ | Exploit Third Party Advisory |
Configurations
History
26 May 2023, 15:02
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:rankmath:seo:*:*:*:*:free:wordpress:*:* |
23 May 2023, 14:57
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-862 | |
CPE | cpe:2.3:a:rankmath:seo:*:*:*:*:*:wordpress:*:* |
Information
Published : 2020-04-07 17:15
Updated : 2024-02-04 21:00
NVD link : CVE-2020-11514
Mitre link : CVE-2020-11514
CVE.ORG link : CVE-2020-11514
JSON object : View
Products Affected
rankmath
- seo
CWE
CWE-862
Missing Authorization