Описание
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.
Ссылки
- ProductRelease Notes
- Product
- ExploitThird Party Advisory
- ProductRelease Notes
- Product
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.40.2 (включая)
cpe:2.3:a:rankmath:seo:*:*:*:*:free:wordpress:*:*
EPSS
Процентиль: 98%
0.56628
Средний
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-862
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.
EPSS
Процентиль: 98%
0.56628
Средний
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-862