S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Dec 1, 2025

CVE-2024-9161 Scanner

CVE-2024-9161 Scanner - Missing Authorization vulnerability in Rank Math SEO plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-9161
6.5
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'update_metadata' function in all versions up to, and including, 1.0.228. This makes it possible for unauthenticated attackers to insert new and update existing metadata beginning with 'rank_math', and delete arbitrary existing user metadata and term metadata. Deleting existing usermeta can cause a loss of access to the administrator dashboard for any registered users, including Administrators.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Rank Math SEO – AI SEO Tools to Dominate SEO Rankingsby rankmath
0
Updated Aug 22, 2026View on NVD →
Detail

Rank Math SEO plugin for WordPress is a popular tool used by website owners, bloggers, and digital marketers to enhance the search engine optimization (SEO) of their websites. It provides various SEO features such as keyword optimization, sitemap generation, and on-page SEO analysis, helping users improve their site's ranking on search engines. The plugin is particularly favored among WordPress users due to its user-friendly interface and integration capabilities. It supports multiple websites and offers advanced options for those looking to optimize their site's visibility. Rank Math helps diagnose SEO issues and provides actionable suggestions, making it a preferred choice for SEO enhancement.

The detected vulnerability in Rank Math SEO plugin involves missing authorization checks within the 'update_metadata' function. This flaw allows unauthenticated attackers to insert, update, or delete metadata without the necessary permissions. The vulnerability affects user and term metadata, which could lead to data loss or unauthorized access changes. This failure to properly validate authentication measures can leave websites vulnerable to manipulation. If exploited, attackers can execute unauthorized operations, severely impacting the site's integrity and access control. Ensuring authorization checks are in place is crucial for maintaining security.

Technically, the vulnerability involves inadequate capability checks on metadata operations. The plugin allows HTTP requests to be sent to specific endpoints, such as 'updateMeta', without requiring proper authentication. These endpoints accept parameters for metadata types and values that can be manipulated by attackers. The plugin does not verify the legitimacy of requests for these operations. A successful attack relies on crafting specific requests to manipulate the internal metadata structures. The presence of JSON responses indicates acceptance of crafted malicious requests, undermining security protocols.

Exploiting this vulnerability could lead to several negative consequences, including data manipulation or deletion. Malicious actors may insert misleading information or erase critical data, causing administration and management challenges. Potential denial of access to legitimate users is another risk, as attackers alter user metadata. Widespread exploitation might disrupt the SEO capabilities of affected websites, undermining their search engine presence. Additionally, loss of trust from users or clients due to perceived negligence in data security could occur.

REFERENCES

Solution Advice
  • Update the Rank Math SEO plugin to version 1.0.229 or later to address this vulnerability.
  • Review and audit user permissions and metadata operations to ensure proper authorization is enforced.
  • Regularly monitor plugin activity logs to detect any unauthorized access or data changes.
  • Implement security monitoring solutions to identify unusual activities related to metadata operations.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-9161 Scanner - Missing Authorization vulnerability in Rank Math SEO plugin for WordPress S4E