PT-2020-12659 · Mythemeshop · Rank Math

Published

2020-04-07

·

Updated

2025-09-18

·

CVE-2020-11515

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Rank Math plugin versions 1.0.40.2 and earlier
Description The issue allows unauthenticated remote attackers to create new URIs that redirect to an external web site via the unsecured "rankmath/v1/updateRedirection" REST API endpoint. This enables attackers to create a new URI with an arbitrary name.
Recommendations For Rank Math plugin versions 1.0.40.2 and earlier, consider disabling access to the "rankmath/v1/updateRedirection" REST API endpoint until a patch is available. Restrict the ability to create new URIs to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2020-11515

Affected Products

Rank Math