CVE-2022-36376: WordPress Rank Math SEO plugin <= 1.0.95 - Server-Side Request Forgery (SSRF) vulnerability
Published Sep 9, 2022
·Updated
Server-Side Request Forgery (SSRF) vulnerability in Rank Math SEO plugin <= 1.0.95 at WordPress.
Affected Software
1 affected component
rankmath Seo Wordpress<=1.0.95
Remediation
Information
Update to 1.0.95.1 or higher version.
Event History
Sep 9, 2022
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-36376?
CVE-2022-36376 has a critical severity rating due to its potential to execute unauthorized requests on behalf of the server.
2
How do I fix CVE-2022-36376?
To fix CVE-2022-36376, update the Rank Math SEO plugin to version 1.0.96 or later.
3
What types of systems are affected by CVE-2022-36376?
CVE-2022-36376 affects WordPress systems using Rank Math SEO plugin versions up to and including 1.0.95.
4
Can CVE-2022-36376 be exploited remotely?
Yes, CVE-2022-36376 can be exploited remotely, allowing an attacker to make unauthorized requests to internal systems.
5
What potential impact does CVE-2022-36376 have on a website?
The impact of CVE-2022-36376 could lead to data exposure, unauthorized actions, or denial of service on the affected WordPress site.