WordPress Plugin SEO by RankMath Security Update via @martinibuster - Website Pro USA
Website Builder,SEO,Social Media Consultant, Hosting, Website Care Plans
31561
post-template-default,single,single-post,postid-31561,single-format-standard,theme-bridge,woocommerce-no-js,ajax_updown,page_not_loaded,,qode-content-sidebar-responsive,columns-3,qode-child-theme-ver-1.0.0,qode-theme-ver-9.2,hide_inital_sticky,wpb-js-composer js-comp-ver-7.9,vc_responsive

WordPress Plugin SEO by RankMath Security Update via @martinibuster

WordPress Plugin SEO by RankMath Security Update via @martinibuster

SEO By RankMath, a popular SEO plugin recently fixed several vulnerabilities. One of the issues fixed allowed a subscriber to reset the plugin settings. Web publishers are encouraged to update their plugin.

Description of SEO By RankMath Vulnerability Fix

The WordPress Vulnerability Database (WPVULNDB) announced the vulnerability in SEO by RankMath in a post.

ADVERTISEMENT
CONTINUE READING BELOW

According to WPVULNDB:

“Allows any authenticated user (with a role as low as subscriber) to reset Settings of the plugin.”

There was also a separate Cross Site Scripting issue that was fixed.

A Cross Site Scripting vulnerability is a relatively common problem that allows an attacker to exploit an interactive part of a site (like a form) and submit code that can (among many things) obtain cookie information as well as upload data or scripts to the site.

RankMath Strengthens Security

The above security issues were fixed in version 1.0.27 of the plugin on June 21, 2019. On June 23rd, RankMath issued another update (1.0.27.2) that further strengthened security.

ADVERTISEMENT
CONTINUE READING BELOW

According to the SEO by RankMath changelog:

“Improved sanitization throughout the plugin”

Sanitization means an extra layer of coding that will stop an unexpected input from breaking a script and allowing an exploit.

For example, if a script expects data with no spaces in it, an input with spaces could in this example break the script. Sanitization is an extra step in the code that anticipates a malevolent input and will close that space to prevent the exploit from happening.

RankMath Responsibly Notifies Users

A changelog is a record of what an update changes and fixes. For every update, a WordPress plugin developer publishes a changelog that a user can read.

ADVERTISEMENT
CONTINUE READING BELOW
Screnshot of SEO by RankMath changelogScrenshot of SEO by RankMath changelogSEO by RankMath responsibly notified users of a security update via their changelog.

It’s important to note that RankMath did the right thing and notified users through their changelog that this update contained a security fix.

Many plugin publishers do not alert users that an update contains a security fix.

Perhaps plugin developers fear harming their brand by acknowledging the existence of a vulnerability. Thus they sneak the fix unannounced, without mentioning it in their changelog.

ADVERTISEMENT
CONTINUE READING BELOW

It may be that some plugin developers hope nobody notices that the plugin contained a vulnerability. In my opinion that is irresponsible. It causes a user to be unaware of the urgency of updating a plugin.

RankMath approached this security update in an honorable and transparent manner. Their changelog accurately notes the security update. That’s a sign of a trusted developer.

Of course, all plugins should be updated as soon as an update is available. Security updates should always be applied right away.

No Comments

Sorry, the comment form is closed at this time.