CVE-2024-13227

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Feb 13, 2025
Updated: Feb 24, 2025
CWE ID 79

Summary

CVE-2024-13227 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress. This issue exists due to insufficient sanitization and escaping of user-supplied attributes in the plugin's Rank Math API. Authenticated attackers with contributor-level access or higher can exploit this vulnerability by injecting arbitrary web scripts. These scripts will execute whenever a user visits an injected page, posing a significant security risk. All versions of the plugin up to and including 1.0.235 are vulnerable to this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share