PoC Index

CVE-2020-11514

CRITICAL 9.8EPSS 9.1%

The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
9.11% chance of exploitation in the next 30 days, 95th percentile
Nuclei
critical · CWE-862
Published
2020-04-07
Updated
2024-08-04

Nuclei templates (1)

References

Related