CVE-2024-4617: Rank Math SEO with AI Best SEO Tools <= 1.0.218 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 1.0.218 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rank Math SEO with AI Best SEO Tools (WordPress plugin)to a version that resolves this vulnerability.Fixed in 1.0.218
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4617?
CVE-2024-4617 is classified as a high-severity vulnerability due to its potential for enabling Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-4617?
To fix CVE-2024-4617, update the Rank Math SEO with AI Best SEO Tools plugin to version 1.0.219 or later.
Who is affected by CVE-2024-4617?
CVE-2024-4617 affects users of the Rank Math SEO with AI Best SEO Tools plugin running versions 1.0.218 and below.
What type of vulnerability is CVE-2024-4617?
CVE-2024-4617 is a Stored Cross-Site Scripting vulnerability due to insufficient input sanitization and output escaping.
Who can exploit CVE-2024-4617?
CVE-2024-4617 can be exploited by authenticated attackers who can craft malicious input to execute their scripts.