CyberRota Analysis
AI-GeneratedThe Rank Math SEO plugin for WordPress prior to version 1.0.277 is vulnerable, allowing users with the Author role and above to overwrite arbitrary post and user metadata without proper authorization checks. This could lead to unauthorized changes to sensitive data, potentially affecting higher-privileged users. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs to the object the user was authorised against, allowing users with the Author role and above to overwrite arbitrary post and user metadata, including that belonging to higher-privileged users.