{"id":"GHSA-j95r-86hx-xwxg","summary":"Rank Math SEO plugin vulnerable to Server-Side Request Forgery","details":"Server-Side Request Forgery (SSRF) vulnerability in Rank Math SEO plugin \u003c= 1.0.95 at WordPress.","aliases":["CVE-2022-36376"],"modified":"2024-02-21T05:51:31.206273Z","published":"2022-09-10T00:00:27Z","database_specific":{"nvd_published_at":"2022-09-09T15:15:00Z","cwe_ids":["CWE-918"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-09-16T13:42:41Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-36376"},{"type":"PACKAGE","url":"https://github.com/rankmath/seo-by-rank-math"},{"type":"WEB","url":"https://patchstack.com/database/vulnerability/seo-by-rank-math/wordpress-rank-math-seo-plugin-1-0-95-server-side-request-forgery-ssrf-vulnerability"},{"type":"WEB","url":"https://rankmath.com/changelog"}],"affected":[{"package":{"name":"rankmath/seo-by-rank-math","ecosystem":"Packagist","purl":"pkg:composer/rankmath/seo-by-rank-math"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.0.95"}]}],"versions":["v1.0.44","v1.0.45","v1.0.46","v1.0.47","v1.0.47.1","v1.0.47.1-beta","v1.0.48","v1.0.48-beta","v1.0.48-beta-2","v1.0.48.1","v1.0.48.2","v1.0.48.2-beta","v1.0.49","v1.0.49-beta","v1.0.49.1-beta","v1.0.50","v1.0.50.1","v1.0.51","v1.0.52","v1.0.52.1","v1.0.52.2","v1.0.52.3","v1.0.53","v1.0.53.1","v1.0.54","v1.0.54.1","v1.0.54.2","v1.0.54.3","v1.0.55","v1.0.56","v1.0.56-beta","v1.0.56.1","v1.0.57","v1.0.57.1","v1.0.58","v1.0.59","v1.0.59.1","v1.0.60","v1.0.60.1","v1.0.61","v1.0.61.1","v1.0.62","v1.0.63","v1.0.64","v1.0.65","v1.0.66","v1.0.66.1","v1.0.67","v1.0.68","v1.0.68.1","v1.0.69","v1.0.69.1","v1.0.69.2","v1.0.70","v1.0.94","v1.0.95"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-j95r-86hx-xwxg/GHSA-j95r-86hx-xwxg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}