First published: Thu Aug 15 2019(Updated: )
The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rank Math SEO | <1.0.27.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14786 has a medium severity rating due to its potential impact on user settings.
To fix CVE-2019-14786, update the Rank Math SEO plugin to version 1.0.27.1 or later.
CVE-2019-14786 affects users of the Rank Math SEO plugin version 1.0.27 or earlier on WordPress.
CVE-2019-14786 is an authenticated settings reset vulnerability affecting the Rank Math SEO plugin.
Yes, non-admin users can exploit CVE-2019-14786 to reset the settings of the Rank Math SEO plugin.