Impact
The vulnerability allows remote actors to run arbitrary PHP code on a WordPress site that hosts the Rank Math SEO plugin. By exploiting the flaw, an attacker can execute arbitrary PHP code within the WordPress environment, potentially compromising the site's application layer. The weakness is classified as CWE-502, an unsafe deserialization issue.
Affected Systems
WordPress installations that have Rank Math SEO plugin version 1.0.276 or older. The issue is limited to the plugin's code base and does not affect other components of WordPress.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. No EPSS score is available, but the lack of an entry in the CISA KEV catalog suggests no public exploits yet. Attackers can potentially exploit the issue remotely from any network that can reach the WordPress site, unless mitigated by network firewall or robust authentication. Based on the description, it is inferred that the attack vector is remote via HTTP(s) traffic that triggers the deserialization routine.
OpenCVE Enrichment