18 Jul 2023

Authenticated Persistent Cross-Site Scripting (XSS) Vulnerability Fixed in Rank Math SEO

The changelog for the latest version of the WordPress plugin Rank Math SEO, which has 2+ million installs, suggested that a security vulnerability had been fixed, but didn’t credit a discoverer. (It did mention a company that redirects vulnerability reports away from developers and WordPress.) Checking in to that, we found that a minor authenticated persistent cross-site scripting (XSS) vulnerability exploitable through a shortcode had been fixed.

Only one change was made in that version, which makes it easy to see what was going on. [Read more]