First published: Tue Apr 07 2020(Updated: )
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint. In other words, this is not an "Open Redirect" issue; instead, it allows the attacker to create a new URI with an arbitrary name (e.g., the /exampleredirect URI).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rank Math SEO | <=1.0.40.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11515 is classified as a critical vulnerability due to its ability to allow unauthenticated attackers to create new URIs.
To fix CVE-2020-11515, update the Rank Math plugin to version 1.0.40.3 or later.
CVE-2020-11515 enables unauthenticated remote attackers to redirect users to external websites through the plugin's REST API.
CVE-2020-11515 affects versions of Rank Math SEO plugin up to and including 1.0.40.2.
No, CVE-2020-11515 is not an Open Redirect issue; it allows the creation of arbitrary URIs that redirect to external sites.