Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress contains a missing capability check on 'update_metadata' in all versions up to 1.0.228, letting unauthenticated attackers insert, update, or delete metadata, including user and term metadata, potentially causing loss of access to the admin dashboard.
id: CVE-2024-9161
info:
name: Rank Math SEO < 1.0.229 - Unauthenticated User and Term Metadata In
...