First published: Sat Oct 05 2024(Updated: )
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'update_metadata' function in all versions up to, and including, 1.0.228. This makes it possible for unauthenticated attackers to insert new and update existing metadata beginning with 'rank_math', and delete arbitrary existing user metadata and term metadata. Deleting existing usermeta can cause a loss of access to the administrator dashboard for any registered users, including Administrators.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rank Math SEO | <=1.0.228 | |
Rank Math SEO | <1.0.229 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9161 has a moderate severity level due to its potential for unauthorized modification and data loss.
To fix CVE-2024-9161, update the Rank Math SEO plugin to version 1.0.229 or later.
CVE-2024-9161 affects all versions of the Rank Math SEO plugin up to and including version 1.0.228.
CVE-2024-9161 puts the site's metadata at risk due to the vulnerability in the 'update_metadata' function.
As of now, there are no public reports of active exploits targeting CVE-2024-9161.