CVE-2024-9161
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Missing Authorization to Unauthenticated User and Term Metadata Insert, Update, and Delete
Record summary
CVE-2024-9161 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.
Description
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'update_metadata' function in all versions up to, and including, 1.0.228. This makes it possible for unauthenticated attackers to insert new and update existing metadata beginning with 'rank_math', and delete arbitrary existing user metadata and term metadata. Deleting existing usermeta can cause a loss of access to the administrator dashboard for any registered users, including Administrators.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 25, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 7, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
AI SEO Tools to Dominate SEO Rankings Plugin for WordPressBrowse Rank Math / AI SEO Tools to Dominate SEO Rankings Plugin for WordPress | VulnCheck | Version data not supplied | |
Rank Math SEO – AI SEO Tools to Dominate SEO RankingsBrowse rankmath / Rank Math SEO – AI SEO Tools to Dominate SEO RankingsDefault status: unaffected | CVE List | Through 1.0.228 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMRank Math SEO < 1.0.229 - Unauthenticated User and Term Metadata Insert/Update/DeletionCVSS 6.5
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress contains a missing capability check on 'update_metadata' in all versions up to 1.0.228, letting unauthenticated attackers insert, update, or delete metadata, including user and term metadata, potentially causing loss of access to the admin dashboard.
Impact
Unauthenticated attackers can modify or delete metadata, leading to data loss and potential denial of access to the admin dashboard.
Remediation
Update to version 1.0.229 or later.
Source: ProjectDiscovery