CVE-2024-13229: Rank Math SEO <= 1.0.235 - Missing Authorization to Authenticated (Contributor+) Arbitrary Schema Deletion
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the updatemetadata() function in all versions up to, and including, 1.0.235. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete any schema metadata assigned to any post.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13229?
CVE-2024-13229 is considered a critical vulnerability due to its potential for unauthorized data loss.
How do I fix CVE-2024-13229?
To fix CVE-2024-13229, update the Rank Math SEO plugin to version 1.0.236 or higher.
Who is affected by CVE-2024-13229?
All versions of the Rank Math SEO plugin up to and including 1.0.235 are affected by CVE-2024-13229.
What causes CVE-2024-13229?
CVE-2024-13229 is caused by a missing capability check in the update_metadata() function.
Can authenticated attackers exploit CVE-2024-13229?
Yes, authenticated attackers can exploit CVE-2024-13229 to perform unauthorized actions that lead to data loss.