What the vulnerability does
01Description
Missing Authorization vulnerability in Rank Math Rank Math SEO PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO PRO: from n/a through 3.0.95.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Rank Math Rank Math SEO PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO PRO: from n/a through 3.0.95.
Explanation of Vulnerability in Simple Terms
Rank Math SEO PRO versions up to 3.0.95 contain an authorization bypass that allows authenticated users to modify site content they should not have access to. The vulnerability requires a valid user account but no special privileges. An attacker with low-level access can alter data integrity on the site.
What an attacker can do
Modify site content or settings without proper permission checks.
Potential impact on your site
Unauthorized users may alter SEO settings, metadata, or other site content managed by the plugin.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges on the site.
Key dates
External resources
Related vulnerabilities