← back
CVE-2020-11514observed exploitation

CVE-2020-11514

40Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 9.1%
from disclosure to weapon
Published on NVDApr 7
VulnCheck+1198d
exploitation probability
9.1%top 5% of all CVEs
observed exploitation
yesVulnCheck
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.
Affected products
n/a · n/a