GHSA-j95r-86hx-xwxg

Suggest an improvement
Source
https://github.com/advisories/GHSA-j95r-86hx-xwxg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-j95r-86hx-xwxg/GHSA-j95r-86hx-xwxg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-j95r-86hx-xwxg
Aliases
  • CVE-2022-36376
Published
2022-09-10T00:00:27Z
Modified
2024-02-21T05:51:31.206273Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Rank Math SEO plugin vulnerable to Server-Side Request Forgery
Details

Server-Side Request Forgery (SSRF) vulnerability in Rank Math SEO plugin <= 1.0.95 at WordPress.

Database specific
{
    "cwe_ids": [
        "CWE-918"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2022-09-16T13:42:41Z",
    "nvd_published_at": "2022-09-09T15:15:00Z",
    "severity": "CRITICAL"
}
References

Affected packages

Packagist / rankmath/seo-by-rank-math

Package

Name
rankmath/seo-by-rank-math
Purl
pkg:composer/rankmath/seo-by-rank-math

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.0.95

Affected versions

v1.*
v1.0.44
v1.0.45
v1.0.46
v1.0.47
v1.0.47.1-beta
v1.0.47.1
v1.0.48-beta
v1.0.48-beta-2
v1.0.48
v1.0.48.1
v1.0.48.2-beta
v1.0.48.2
v1.0.49-beta
v1.0.49
v1.0.49.1-beta
v1.0.50
v1.0.50.1
v1.0.51
v1.0.52
v1.0.52.1
v1.0.52.2
v1.0.52.3
v1.0.53
v1.0.53.1
v1.0.54
v1.0.54.1
v1.0.54.2
v1.0.54.3
v1.0.55
v1.0.56-beta
v1.0.56
v1.0.56.1
v1.0.57
v1.0.57.1
v1.0.58
v1.0.59
v1.0.59.1
v1.0.60
v1.0.60.1
v1.0.61
v1.0.61.1
v1.0.62
v1.0.63
v1.0.64
v1.0.65
v1.0.66
v1.0.66.1
v1.0.67
v1.0.68
v1.0.68.1
v1.0.69
v1.0.69.1
v1.0.69.2
v1.0.70
v1.0.94
v1.0.95

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-j95r-86hx-xwxg/GHSA-j95r-86hx-xwxg.json"