Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c2qp-gp7h-j46p

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.

The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.

EPSS

Процентиль: 98%
0.56628
Средний

9.8 Critical

CVSS3

Дефекты

CWE-269
CWE-862

Связанные уязвимости

CVSS3: 9.8
nvd
почти 6 лет назад

The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.

EPSS

Процентиль: 98%
0.56628
Средний

9.8 Critical

CVSS3

Дефекты

CWE-269
CWE-862