Rank Math SEO <= 1.0.40.2 - Redirect Creation via Unprotected REST API Endpoint
2020-03-25 00:00
RamStrategic Overview
StatusPatched in 1.0.41
Affected PluginRank Math SEO – AI SEO Tools to Dominate SEO Rankings
Affected Version
<= 1.0.40CVSS7.4High
CVE
CVE-2020-11515Vulnerability Overview
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint. In other words, this is not an "Open Redirect" issue; instead, it allows the attacker to create a new URI with an arbitrary name (e.g., the /exampleredirect URI).
Technical Analysis
REMEDIATION: Update to version 1.0.41, or a newer patched version --- IDENTIFIER: CWE-288 (Authentication Bypass Using an Alternate Path or Channel) The product requires authentication, but the product has an alternate path or channel that does not require authentication.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C