First published: Thu Feb 13 2025(Updated: )
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the update_metadata() function in all versions up to, and including, 1.0.235. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete any schema metadata assigned to any post.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rank Math | <=1.0.235 | |
Rank Math SEO | <1.0.236 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-13229 is considered a critical vulnerability due to its potential for unauthorized data loss.
To fix CVE-2024-13229, update the Rank Math SEO plugin to version 1.0.236 or higher.
All versions of the Rank Math SEO plugin up to and including 1.0.235 are affected by CVE-2024-13229.
CVE-2024-13229 is caused by a missing capability check in the update_metadata() function.
Yes, authenticated attackers can exploit CVE-2024-13229 to perform unauthorized actions that lead to data loss.