Access violation vulnerability in Rankology SEO – On-site SEO 2.2.3

The Rankology SEO plugin for WordPress has a vulnerability that allows unauthorized changes to be made to data. This can lead to an increase in privileges for attackers. The issue is due to a missing capability check in the save_rankology_settings() function in all versions up to 2.2.3. This means that attackers with at least Subscriber-level access can change various options on the WordPress site. They could potentially change the default registration role to administrator and enable user registration, giving them administrative access to the site.

Detected in:

Rankology SEO – All in One SEO & Analytics fixed vulnerable versions: >= * <= 2.2.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.