There is a vulnerability in RankMath

#984606
  • Resolved Yancy Y.
    Rank Math free

    There is a vulnerability in RankMath that allows clients to automatically access my website as an administrator. I accessed my website using a browser that I had never used before, and I found that the front end of the site was displayed as logged in as an administrator, showing RankMath-related information

    chinassistant.com

Viewing 10 replies - 1 through 10 (of 10 total)
  • Hello,

    We apologize for the issue you are facing regarding the vulnerability in Rank Math. It’s crucial to ensure that your website’s security is maintained. We recommend that you reply to this ticket with any additional details you may have, and a human agent from the Rank Math Support team will take over and assist you further.

    Thank you for bringing this concern to our attention. Please include any relevant information that could help us address the issue effectively.

    Yancy Y.
    Rank Math free

    Hello,

    I have updated the sensitive data as requested. Can you please check further?

    Thank you.

    Yancy Y.
    Rank Math free

    https://imgur.com/a/obYW0kG when i visit https://chinassistant.com/repacking-service-pricing-and-amazon-fba-prep/ , the admin info is loaded and exposed to the public

    Hello,

    The screenshot you shared is our Analytics Stats bar, which only shows when you are logged in on your WordPress Dashboard:
    https://rankmath.com/kb/analytics-stats-bar/

    You will also see the WordPress toolbar above it, meaning you are viewing the page as a user from your WordPress.

    To view your pages without the admin info you’re referring to, you can use a different internet browser or simply go into incognito mode.

    Looking forward to helping you.

    Yancy Y.
    Rank Math free

    i got your point , but you didn’t read carefully , what I mean is , even I download a new browser and paste the URL in a new browser, this “logged in info” or “toorbar” will display to a guest. that is quite strange and weird

    Hello,

    We checked your website but we are not able to replicate this as you can see in this screenshot:

    You can try to temporarily deactivate the Rank Math plugin on your website, and visit the page with the same browser, and check if you’re still able to see the top admin bar or not.

    You can also share a screencast with us using a tool like https://loom.com so that we can check this as well.

    Looking forward to helping you.

    Thank you.

    Yancy Y.
    Rank Math free

    hi, i do have SEO settings for each page, if I deactivate the plugin, what will happen to each page

    Hello,

    All the SEO elements will be disabled.

    Please try recording a video screencast from your end showing the issue using the tool we previously shared.

    Make sure to open a fresh incognito tab and visit the affected page.

    Let us know how that goes.

    how to send you a video ? can you offer me email or any practical ways ? i did a test , recently I am building my website, so all the time I clear the cache from cloudflare, wp backend and my chrome, and I tested many times on different device, ” when I open my website URL in a new device, the “admin log in” info will be displayed with rankmath toolbar . this is a disaster

    Hello,

    Sorry for the inconvenience.

    You can send the video to our support email address: s******@r***********

    Please make sure to ping us here once you have sent the file or the link to the video.

    Looking forward to helping you.

    Hello,

    Since we did not hear back from you for 15 days, we are assuming that you found the solution. We are closing this support ticket.

    If you still need assistance or any other help, please feel free to open a new support ticket, and we will be more than happy to assist.

    Thank you.

Viewing 10 replies - 1 through 10 (of 10 total)

The ticket ‘There is a vulnerability in RankMath’ is closed to new replies.