PHP object injection available via deserialization of untrusted input ‘set_redirections’ function. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP object.
This vulnerability affects the following application versions:
- Rank Math SEO 1.0.215
- Rank Math SEO 1.0.215.1
- Rank Math SEO 1.0.216
- Rank Math SEO 1.0.217
- Rank Math SEO 1.0.218
- Rank Math SEO 1.0.219
- Rank Math SEO 1.0.220
- Rank Math SEO 1.0.221
- Rank Math SEO 1.0.222
- Rank Math SEO 1.0.223
- Rank Math SEO 1.0.224
- Rank Math SEO 1.0.225
- Rank Math SEO 1.0.226
- Rank Math SEO 1.0.227
- Rank Math SEO 1.0.227.1
- Rank Math SEO 1.0.228