Stored Cross-Site Scripting in Rank Math SEO Plugin for WordPress
CVE-2024-4627
What is CVE-2024-4627?
The Rank Math SEO plugin for WordPress versions prior to 1.0.219 is susceptible to Stored Cross-Site Scripting attacks. This vulnerability arises due to the failure to properly sanitize and escape certain settings within the plugin. Consequently, users with access to General Settings, including those granted lower-level permissions through the Role Manager feature, can exploit this vulnerability to inject malicious scripts. This risk persists even when the 'unfiltered_html' capability is restricted, posing a significant security threat, particularly in multisite configurations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published