CVE-2020-11514
CRITICAL 9.8EPSS 9.1%
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 9.11% chance of exploitation in the next 30 days, 95th percentile
- Nuclei
- critical · CWE-862
- Published
- 2020-04-07
- Updated
- 2024-08-04