Vulnerabilities
Vulnerable Software
Rankmath:  >> Seo  >> 1.0.10  Security Vulnerabilities
Server-Side Request Forgery (SSRF) vulnerability in Rank Math SEO plugin <= 1.0.95 at WordPress.
CVSS Score
6.8
EPSS Score
0.006
Published
2022-09-09
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.
CVSS Score
9.8
EPSS Score
0.566
Published
2020-04-07
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint. In other words, this is not an "Open Redirect" issue; instead, it allows the attacker to create a new URI with an arbitrary name (e.g., the /exampleredirect URI).
CVSS Score
6.1
EPSS Score
0.009
Published
2020-04-07
The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb parameter.
CVSS Score
6.5
EPSS Score
0.002
Published
2019-08-15


Contact Us

Shodan ® - All rights reserved