#VU26595 Permissions, Privileges, and Access Controls in WordPress SEO Plugin - Rank Math - CVE-2020-11514
Published: April 6, 2020 / Updated: April 8, 2020
WordPress SEO Plugin - Rank Math
Rank Math
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the affected plugin registers the "rankmath/v1/updateMeta" REST-API endpoint, which fails to include a "permission_callback" used for capability checking. A remote attacker can send a specially crafted request and gain administrator privileges on the target system.