CVE-2020-11515: Medium severity rank math seo vulnerability
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint. In other words, this is not an "Open Redirect" issue; instead, it allows the attacker to create a new URI with an arbitrary name (e.g., the /exampleredirect URI).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11515?
CVE-2020-11515 is classified as a critical vulnerability due to its ability to allow unauthenticated attackers to create new URIs.
How do I fix CVE-2020-11515?
To fix CVE-2020-11515, update the Rank Math plugin to version 1.0.40.3 or later.
What type of attack does CVE-2020-11515 enable?
CVE-2020-11515 enables unauthenticated remote attackers to redirect users to external websites through the plugin's REST API.
What software versions are affected by CVE-2020-11515?
CVE-2020-11515 affects versions of Rank Math SEO plugin up to and including 1.0.40.2.
Is CVE-2020-11515 an Open Redirect issue?
No, CVE-2020-11515 is not an Open Redirect issue; it allows the creation of arbitrary URIs that redirect to external sites.