CVE-2020-11514
Summary
| CVE | CVE-2020-11514 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-07 17:15:00 UTC |
| Updated | 2023-05-26 15:02:00 UTC |
| Description | The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| The Official Rank Math SEO Changelog & Release Notes | MISC | rankmath.com | Product, Release Notes |
| WordPress SEO Plugin – Rank Math | WordPress.org | MISC | wordpress.org | Product |
| Critical Vulnerabilities Affecting Over 200,000 Sites Patched in Rank Math SEO Plugin | MISC | www.wordfence.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.