Описание
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs to the object the user was authorised against, allowing users with the Author role and above to overwrite arbitrary post and user metadata, including that belonging to higher-privileged users.
EPSS
Процентиль: 9%
0.00193
Низкий
4.9 Medium
CVSS3
Дефекты
CWE-639
Связанные уязвимости
CVSS3: 4.9
github
21 день назад
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs to the object the user was authorised against, allowing users with the Author role and above to overwrite arbitrary post and user metadata, including that belonging to higher-privileged users.
EPSS
Процентиль: 9%
0.00193
Низкий
4.9 Medium
CVSS3
Дефекты
CWE-639