A critical privilege escalation flaw in the WordPress SEO plugin Rank Math plugin can allow registered users to gain administrator privileges. The plugin is currently installed on more than 200,000 sites. The issue resides in an unprotected REST-API endpoint, the issue could be exploited by an unauthenticated attacker to update arbitrary metadata, which ones that could grant or revoke administrative privileges for any registered user on the site. A second flaw made it possible for an attacker to create redirects from almost any location on the website to any destination of their choice. The number of attacks attempting to exploit vulnerabilities in WordPress plugins continues to increase.”]
Source: https://securityaffairs.co/wordpress/100848/hacking/rank-math-wordpress-bug.html

