6.1
CVSSv3

CVE-2020-11515

Published: 07/04/2020 Updated: 26/05/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

The Rank Math plugin up to and including 1.0.40.2 for WordPress allows unauthenticated remote malicious users to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint. In other words, this is not an "Open Redirect" issue; instead, it allows the malicious user to create a new URI with an arbitrary name (e.g., the /exampleredirect URI).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rankmath seo