CVE-2020-11515
The Rank Math SEO plugin prior to version 1.0.0.41 contained an insecure REST API endpoint at rankmath/v1/updateRedirection that lacked proper permission verification, allowing unauthenticated users to call the update_redirection function. This function enabled attackers to create new redirects or modify existing ones throughout the site, though with the constraint that redirects could not point to actual server files, folders, or the homepage. While this limitation reduced the potential scope of damage, malicious actors could still establish redirects from most site locations including posts and pages to external or malicious destinations.
Based on public CVE data (MITRE/NVD).