The Rank Math plugin through 1.0.40.2 for WordPress...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated May 23, 2023
Description
Published by the National Vulnerability Database
Apr 7, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
May 23, 2023
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.
References