CVE-2024-13227
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-13227 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress. This issue exists due to insufficient sanitization and escaping of user-supplied attributes in the plugin's Rank Math API. Authenticated attackers with contributor-level access or higher can exploit this vulnerability by injecting arbitrary web scripts. These scripts will execute whenever a user visits an injected page, posing a significant security risk. All versions of the plugin up to and including 1.0.235 are vulnerable to this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Rank Math SEO
Affected Vendors
- Rankmath