The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.
References
Link | Resource |
---|---|
https://rankmath.com/changelog/ | Product Release Notes |
https://wordpress.org/plugins/seo-by-rank-math/#developers | Product |
https://www.wordfence.com/blog/2020/03/critical-vulnerabilities-affecting-over-200000-sites-patched-in-rank-math-seo-plugin/ | Exploit Third Party Advisory |
https://rankmath.com/changelog/ | Product Release Notes |
https://wordpress.org/plugins/seo-by-rank-math/#developers | Product |
https://www.wordfence.com/blog/2020/03/critical-vulnerabilities-affecting-over-200000-sites-patched-in-rank-math-seo-plugin/ | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 04:58
Type | Values Removed | Values Added |
---|---|---|
References | () https://rankmath.com/changelog/ - Product, Release Notes | |
References | () https://wordpress.org/plugins/seo-by-rank-math/#developers - Product | |
References | () https://www.wordfence.com/blog/2020/03/critical-vulnerabilities-affecting-over-200000-sites-patched-in-rank-math-seo-plugin/ - Exploit, Third Party Advisory |
26 May 2023, 15:02
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:rankmath:seo:*:*:*:*:free:wordpress:*:* |
Information
Published : 2020-04-07 17:15
Updated : 2024-11-21 04:58
NVD link : CVE-2020-11514
Mitre link : CVE-2020-11514
CVE.ORG link : CVE-2020-11514
JSON object : View
Products Affected
rankmath
- seo
CWE
CWE-862
Missing Authorization