What the vulnerability does
01Description
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Rank Math SEO plugin <= 1.0.119 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Rank Math SEO plugin <= 1.0.119 versions.
Explanation of Vulnerability in Simple Terms
Rank Math SEO versions up to 1.0.119 contain a stored cross-site scripting (XSS) vulnerability. An authenticated user with low privileges can inject malicious scripts that execute in the browsers of other users, including administrators. The vulnerability requires user interaction—typically clicking a link or visiting a crafted page—but can affect the entire site scope due to the stored nature of the attack.
What an attacker can do
Inject malicious scripts that run in other users' browsers, potentially stealing session tokens or performing actions as those users.
Potential impact on your site
Authenticated users can compromise other users' accounts or sessions, including admin accounts, without requiring admin privileges themselves.
Conditions required to exploit
Attacker must have a low-privilege account on the site; victim must visit a page containing the injected payload.
Key dates
External resources
Related vulnerabilities