CVE-2020-11514
9.8
CRITICAL · CVSS 3.1 · EPSS 9.1% (pctl 95)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 9.11% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-862 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-04-07 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| rankmath | seo |
References
- https://rankmath.com/changelog/
- https://wordpress.org/plugins/seo-by-rank-math/#developers
- https://www.wordfence.com/blog/2020/03/critical-vulnerabilities-affecting-over-200000-sites-patched-in-rank-math-seo-plugin/
- https://rankmath.com/changelog/
- https://wordpress.org/plugins/seo-by-rank-math/#developers
- https://www.wordfence.com/blog/2020/03/critical-vulnerabilities-affecting-over-200000-sites-patched-in-rank-math-seo-plugin/
→ the Explorer · watch your stack · NVD