CVE-2020-11514
The Rank Math SEO plugin before version 1.0.0.41 exposed a REST API endpoint called rankmath/v1/updateMeta that lacked proper permission verification. Because the endpoint was accessible without authentication, attackers could invoke the update_metadata function to modify post slugs, delete or alter metadata across posts, comments, terms, and users. This vulnerability allowed unauthenticated attackers to manipulate user capabilities stored in the usermeta table, potentially granting themselves or other users administrative access.
Based on public CVE data (MITRE/NVD).