CVE-2020-11515
Rank Math SEO <= 1.0.40.2 - Redirect Creation via Unprotected REST API Endpoint
highAuthentication Bypass Using an Alternate Path or Channel
7.4
CVSS Score
7.4
CVSS Score
high
Severity
1.0.41
Patched in
1399d
Time to patch
Description
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint. In other words, this is not an "Open Redirect" issue; instead, it allows the attacker to create a new URI with an arbitrary name (e.g., the /exampleredirect URI).
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:HAttack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
None
Confidentiality
None
Integrity
High
Availability
Technical Details
Affected versions
<=1.0.40PublishedMarch 25, 2020
Last updatedJanuary 22, 2024
Affected pluginseo-by-rank-math
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.