cleantalk
Vulnerabilities and Security Researches

Rank Math SEO with AI SEO Tools, 70920f607d8f198be39c3b0a39139c2b6ebf783c

Published on
Jan 30, 2023
Research Description
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.107.3 RankMath SEO <= 1.0.107.2 - Authenticated (Contributor+) Local File Inclusion The RankMath SEO plugin for WordPress is vulnerable to Local File Inclusion via the 'update_schemas' and 'get_snippet_content' functions. This allows authenticated attackers, with contributor-level permissions and above, to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls or obtain sensitive data.
Affected versions
max 1.0.107.3.
Status
vulnerable