Impact
The Rank Math SEO plugin contains a broken access control flaw that allows users with subscriber privileges to reach and manipulate functions that should only be available to administrators. In practice this means that a low‑privilege account can execute privileged API requests, modify plugin settings, or read sensitive site information, undermining the confidentiality, integrity and availability of the website.
Affected Systems
All WordPress installations that have the Rank Math SEO plugin version 1.0.271 or earlier are affected. The issue manifests when a subscriber or any account with a non‑administrator role interacts with the plugin’s administrative endpoints.
Risk and Exploitability
The CVSS score of 6.5 categorizes the vulnerability as medium severity, and the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to authenticate to the site using a subscriber account and then send HTTP requests to the plugin’s admin URLs that lack proper authorization checks, making the vector web‑based and requiring the user to be logged in.
OpenCVE Enrichment