Impact
Incorrect privilege assignment within the Rankology SEO – On-site SEO plugin allows attackers to gain higher privileges on the WordPress site. The vulnerability provides a path for privilege escalation, enabling a lower‑privileged user to obtain administrative capabilities. This can lead to full site compromise, including content manipulation, installation of additional malicious plugins, and unauthorized access to sensitive data.
Affected Systems
Any installation of the Rankology SEO – On-site SEO plugin from any version up to and including 2.2.4 is affected. This includes WordPress sites that have not applied an update to the plugin after that version threshold. No specific WordPress core version limitation is documented.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score of < 1% suggests the overall exploitation probability is low, yet the impact remains high. The vulnerability is not listed in the CISA KEV catalog at this time. Based on the description, it is inferred that the attack vector requires authenticated access to the WordPress site and interaction with the plugin's privileged operations. An attacker with a non‑administrator account could abuse the flaw to elevate privileges to administrator level, granting full control over the site.
OpenCVE Enrichment
EUVD