Vulnerabilities > CVE-2019-14786 - Missing Authorization vulnerability in Rankmath SEO

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
rankmath
CWE-862

Summary

The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb parameter.

Common Weakness Enumeration (CWE)