Rank Math SEO Plugin Vulnerability Exposes 2 Million WordPress Sites
ID: cb0d4e95-2827-5dd9-9acf-ac587ef42714
STIX ID: report--cb0d4e95-2827-5dd9-9acf-ac587ef42714
Feed Name: The Cyber Express
Threat Score
A Stored Cross-Site Scripting (CVE-2024-2536) in the Rank Math SEO with AI plugin allows authenticated contributors to inject and store malicious scripts via the HowTo block attributes in versions up to 1.0.214, potentially affecting over two million WordPress sites; Wordfence disclosed the issue and Rank Math has released patches, so site administrators are advised to apply updates immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
