The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'update_metadata' function in all versions up to, and including, 1.0.228. This makes it possible for unauthenticated attackers to insert new and update existing metadata beginning with 'rank_math', and delete arbitrary existing user metadata and term metadata. Deleting existing usermeta can cause a loss of access to the administrator dashboard for any registered users, including Administrators.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Jan 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Rankmath
Rankmath seo |
|
CPEs | cpe:2.3:a:rankmath:seo:*:*:*:*:free:wordpress:*:* | |
Vendors & Products |
Rankmath
Rankmath seo |
Mon, 07 Oct 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 05 Oct 2024 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'update_metadata' function in all versions up to, and including, 1.0.228. This makes it possible for unauthenticated attackers to insert new and update existing metadata beginning with 'rank_math', and delete arbitrary existing user metadata and term metadata. Deleting existing usermeta can cause a loss of access to the administrator dashboard for any registered users, including Administrators. | |
Title | Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Missing Authorization to Unauthenticated User and Term Metadata Insert, Update, and Delete | |
Weaknesses | CWE-862 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-05T11:21:19.388Z
Updated: 2024-10-07T16:14:57.624Z
Reserved: 2024-09-24T18:07:48.981Z
Link: CVE-2024-9161

Updated: 2024-10-07T16:14:44.081Z

Status : Analyzed
Published: 2024-10-05T12:15:02.897
Modified: 2025-01-29T18:56:32.393
Link: CVE-2024-9161

No data.