Known CVE
Rank Math SEO <= 1.0.40.2 - Privilege Escalation via Unprotected REST API Endpoint
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.
CVE-2020-11514
Critical2020CVSS 9.8CWE-862
cve2020 · wordpress · wordfence · seo-by-rank-math · wp-plugin · priv-esc · unauth · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website