plugin

Seo By Rank Math Vulnerabilities

49 known security issues reported for the Seo By Rank Math WordPress plugin. Most recent disclosed Jul 31, 2026.

1 critical 5 high 17 medium

Running Seo By Rank Math on your site? Check whether your installed version is affected.

Scan your site free

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.274.1 - Unauthenticated Stored Cross-Site Scripting

high

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.274.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...

CVSS:
7.2
Affected:
up to 1.0.274.1
Fixed in:
1.0.275
Disclosed:
Jul 31, 2026

CVE-2026-66702 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.271 - Missing Authorization

medium

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.0.271. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unautho...

CVSS:
4.3
Affected:
up to 1.0.271
Fixed in:
1.0.271.1
Disclosed:
Jun 3, 2026

CVE-2026-34892 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.271 - Missing Authorization to Unauthenticated Homepage Settings Modification

medium

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the update_site_editor_homepage function in all versions up to, and including, 1.0.271. This makes it possible for unauthenticated attackers to modify several plugin s...

CVSS:
5.3
Affected:
up to 1.0.271
Fixed in:
1.0.271.1
Disclosed:
May 28, 2026

CVE-2025-12714 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] <= 1.0.252.1 (unfixed)

unknown

[en] Insertion of Sensitive Information Into Sent Data vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Retrieve Embedded Sensitive Data.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1.

Affected:
up to 1.0.252.1
Fix:
No patched version reported
Disclosed:
Oct 31, 2025

CVE-2025-64351 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] <= 1.0.252.1 (unfixed)

unknown

[en] Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1.

Affected:
up to 1.0.252.1
Fix:
No patched version reported
Disclosed:
Oct 31, 2025

CVE-2025-64350 on NVD →

Rank Math SEO <= 1.0.252.1 - Authenticated (Subscriber+) Information Exposure

medium

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.252.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 1.0.252.1
Fixed in:
1.0.253
Disclosed:
Sep 11, 2025

CVE-2025-64351 on NVD →

Rank Math SEO <= 1.0.252.1 - Missing Authorization

medium

The Rank Math SEO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the track() function in versions up to, and including, 1.0.252.1. This makes it possible for authenticated attackers, with author-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.0.252.1
Fixed in:
1.0.253
Disclosed:
Sep 11, 2025

CVE-2025-64350 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.236

unknown

[en] The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Rank Math API in all versions up to, and including, 1.0.235 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...

Affected:
up to 1.0.236
Fixed in:
1.0.236
Disclosed:
Feb 13, 2025

CVE-2024-13227 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.236

unknown

[en] The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the update_metadata() function in all versions up to, and including, 1.0.235. This makes it possible for authenticated attackers, with Contributor-level acc...

Affected:
up to 1.0.236
Fixed in:
1.0.236
Disclosed:
Feb 13, 2025

CVE-2024-13229 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.235 - Authenticated (Contributor+) Stored Cross-Site Scripting via Rank Math API

medium

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Rank Math API in all versions up to, and including, 1.0.235 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...

CVSS:
6.4
Affected:
up to 1.0.235
Fixed in:
1.0.236
Disclosed:
Feb 12, 2025

CVE-2024-13227 on NVD →

Rank Math SEO <= 1.0.235 - Missing Authorization to Authenticated (Contributor+) Arbitrary Schema Deletion

medium

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the update_metadata() function in all versions up to, and including, 1.0.235. This makes it possible for authenticated attackers, with Contributor-level access a...

CVSS:
4.3
Affected:
up to 1.0.235
Fixed in:
1.0.236
Disclosed:
Feb 12, 2025

CVE-2024-13229 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.232

unknown

[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Rank Math SEO allows Code Injection.This issue affects Rank Math SEO: from n/a through 1.0.231.

Affected:
up to 1.0.232
Fixed in:
1.0.232
Disclosed:
Nov 28, 2024

CVE-2024-11620 on NVD →

Rank Math SEO <= 1.0.231 - .htaccess File Manipulation to Remote Code Execution

high

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.231. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.

CVSS:
7.2
Affected:
up to 1.0.231
Fixed in:
1.0.232
Disclosed:
Nov 22, 2024

CVE-2024-11620 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.229

unknown

[en] The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'update_metadata' function in all versions up to, and including, 1.0.228. This makes it possible for unauthenticated attackers to inser...

Affected:
up to 1.0.229
Fixed in:
1.0.229
Disclosed:
Oct 5, 2024

CVE-2024-9161 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.229

unknown

[en] The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.228 via deserialization of untrusted input 'set_redirections' function. This makes it possible for authenticated attackers, with Administrator-level access...

Affected:
up to 1.0.229
Fixed in:
1.0.229
Disclosed:
Oct 5, 2024

CVE-2024-9314 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Authenticated (Administrator+) PHP Object Injection

high

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.228 via deserialization of untrusted input 'set_redirections' function. This makes it possible for authenticated attackers, with Administrator-level access and a...

CVSS:
7.2
Affected:
up to 1.0.228
Fixed in:
1.0.229
Disclosed:
Oct 4, 2024

CVE-2024-9314 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Missing Authorization to Unauthenticated User and Term Metadata Insert, Update, and Delete

medium

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'update_metadata' function in all versions up to, and including, 1.0.228. This makes it possible for unauthenticated attackers to insert new...

CVSS:
6.5
Affected:
up to 1.0.228
Fixed in:
1.0.229
Disclosed:
Oct 4, 2024

CVE-2024-9161 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.219

unknown

[en] The Rank Math SEO WordPress plugin before 1.0.219 does not sanitise and escape some of its settings, which could allow users with access to the General Settings (by default admin, however such access can be given to lower roles via the Role Manager feature of the Rank Math SEO WordPress plugin before 1.0.219) to...

Affected:
up to 1.0.219
Fixed in:
1.0.219
Disclosed:
Jul 2, 2024

CVE-2024-4627 on NVD →

Rank Math SEO <= 1.0.218 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.218 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...

CVSS:
4.4
Affected:
up to 1.0.218
Fixed in:
1.0.219
Disclosed:
Jun 11, 2024

CVE-2024-4627 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.119.1

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rank Math Rank Math SEO allows Path Traversal.This issue affects Rank Math SEO: from n/a through 1.0.107.2.

Affected:
up to 1.0.119.1
Fixed in:
1.0.119.1
Disclosed:
May 17, 2024

CVE-2023-23888 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.219

unknown

[en] The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 1.0.218 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissi...

Affected:
up to 1.0.219
Fixed in:
1.0.219
Disclosed:
May 16, 2024

CVE-2024-4617 on NVD →

Rank Math SEO with AI Best SEO Tools <= 1.0.218 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 1.0.218 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions a...

CVSS:
6.4
Affected:
up to 1.0.218
Fixed in:
1.0.219-beta
Disclosed:
May 15, 2024

CVE-2024-4617 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.218

unknown

[en] The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘textAlign’ parameter in versions up to, and including, 1.0.217 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level p...

Affected:
up to 1.0.218
Fixed in:
1.0.218
Disclosed:
May 9, 2024

CVE-2024-4335 on NVD →

Rank Math SEO with AI Best SEO Tools <= 1.0.217 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘textAlign’ parameter in versions up to, and including, 1.0.217 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permis...

CVSS:
6.4
Affected:
up to 1.0.217
Fixed in:
1.0.218
Disclosed:
May 3, 2024

CVE-2024-4335 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.217

unknown

[en] The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's HowTo and FAQ widgets in all versions up to, and including, 1.0.216 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...

Affected:
up to 1.0.217
Fixed in:
1.0.217
Disclosed:
Apr 23, 2024

CVE-2024-3665 on NVD →

Rank Math SEO with AI SEO Tools <= 1.0.216 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleWrapper'

medium

The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's HowTo and FAQ widgets in all versions up to, and including, 1.0.216 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta...

CVSS:
6.4
Affected:
up to 1.0.216
Fixed in:
1.0.217
Disclosed:
Apr 22, 2024

CVE-2024-3665 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.215

unknown

[en] The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HowTo block attributes in all versions up to, and including, 1.0.214 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke...

Affected:
up to 1.0.215
Fixed in:
1.0.215
Disclosed:
Apr 9, 2024

CVE-2024-2536 on NVD →

Rank Math SEO with AI SEO Tools <= 1.0.214 - Authenticated(Contributor+) Stored Cross-Site Scripting via HowTo block attributes

medium

The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HowTo block attributes in all versions up to, and including, 1.0.214 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w...

CVSS:
6.4
Affected:
up to 1.0.214
Fixed in:
1.0.215
Disclosed:
Mar 21, 2024

CVE-2024-2536 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.119.1

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Rank Math SEO plugin <= 1.0.119 versions.

Affected:
up to 1.0.119.1
Fixed in:
1.0.119.1
Disclosed:
Aug 5, 2023

CVE-2023-32600 on NVD →

Rank Math SEO <= 1.0.119 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Rank Math SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.0.119 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level an...

CVSS:
6.4
Affected:
up to 1.0.119.1
Fixed in:
1.0.119.1
Disclosed:
Jul 17, 2023

CVE-2023-32600 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.119.1

unknown

The Rank Math SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.0.119 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level an...

Affected:
up to 1.0.119.1
Fixed in:
1.0.119.1
Disclosed:
Jul 17, 2023

RankMath SEO <= 1.0.107.2 - Authenticated (Contributor+) Local File Inclusion

medium

The RankMath SEO plugin for WordPress is vulnerable to Local File Inclusion via the 'update_schemas' and 'get_snippet_content' functions. This allows authenticated attackers, with contributor-level permissions and above, to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in...

CVSS:
6.5
Affected:
up to 1.0.107.2
Fixed in:
1.0.107.3
Disclosed:
Jan 30, 2023

CVE-2023-23888 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.107.3

unknown

The RankMath SEO plugin for WordPress is vulnerable to Local File Inclusion via the 'update_schemas' and 'get_snippet_content' functions. This allows authenticated attackers, with contributor-level permissions and above, to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in...

Affected:
up to 1.0.107.3
Fixed in:
1.0.107.3
Disclosed:
Jan 30, 2023

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.95.1

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in Rank Math SEO plugin <= 1.0.95 at WordPress.

Affected:
up to 1.0.95.1
Fixed in:
1.0.95.1
Disclosed:
Sep 9, 2022

CVE-2022-36376 on NVD →

Rank Math SEO <= 1.0.95 - Server-Side Request Forgery

medium

The Rank Math SEO plugin for WordPress is vulnerable to Server Side Request Forgery in versions up to, and including 1.0.95, due to insufficient user input validation.

CVSS:
5.4
Affected:
up to 1.0.95
Fixed in:
1.0.95.1
Disclosed:
Aug 12, 2022

CVE-2022-36376 on NVD →

Rank Math SEO <= 1.0.42.1 - Missing Authorization

medium

The Rank Math SEO plugin for WordPress is vulnerable to authorization bypass due to missing access controls on its "disable competitor plugins" functionality in versions up to, and including, 1.0.42.1. This makes it possible for subscriber-level attackers to disable other SEO or sitemap plugins on the site.

CVSS:
5.4
Affected:
up to 1.0.42.2
Fixed in:
1.0.42.2
Disclosed:
Apr 18, 2020

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.42.2

unknown

The Rank Math SEO plugin for WordPress is vulnerable to authorization bypass due to missing access controls on its "disable competitor plugins" functionality in versions up to, and including, 1.0.42.1. This makes it possible for subscriber-level attackers to disable other SEO or sitemap plugins on the site.

Affected:
up to 1.0.42.2
Fixed in:
1.0.42.2
Disclosed:
Apr 18, 2020

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.0.41

unknown

[en] The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint. In other words, this is not an "Open Redirect" issue; instead, it allows the attacker to create a...

Affected:
up to 1.0.0.41
Fixed in:
1.0.0.41
Disclosed:
Apr 7, 2020

CVE-2020-11515 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.0.41

unknown

[en] The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.

Affected:
up to 1.0.0.41
Fixed in:
1.0.0.41
Disclosed:
Apr 7, 2020

CVE-2020-11514 on NVD →

Rank Math SEO <= 1.0.40.2 - Privilege Escalation via Unprotected REST API Endpoint

critical

The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.

CVSS:
9.8
Affected:
up to 1.0.41
Fixed in:
1.0.41
Disclosed:
Mar 25, 2020

CVE-2020-11514 on NVD →

Rank Math SEO <= 1.0.40.2 - Redirect Creation via Unprotected REST API Endpoint

high

The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint. In other words, this is not an "Open Redirect" issue; instead, it allows the attacker to create a new...

CVSS:
7.4
Affected:
up to 1.0.40
Fixed in:
1.0.41
Disclosed:
Mar 25, 2020

CVE-2020-11515 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27.1

unknown

[en] The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb parameter.

Affected:
up to 1.0.27.1
Fixed in:
1.0.27.1
Disclosed:
Aug 15, 2019

CVE-2019-14786 on NVD →

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27.1

unknown

Authenticated Settings Reset vulnerability found in WordPress SEO By Rank Math plugin (versions <= 1.0.27).

Affected:
up to 1.0.27.1
Fixed in:
1.0.27.1
Disclosed:
Jun 25, 2019

Rank Math SEO <= 1.0.27 - Authenticated Settings Reset via reset-cmb Parameter

medium

The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb parameter.

CVSS:
6.5
Affected:
up to 1.0.27.1
Fixed in:
1.0.27.1
Disclosed:
Jun 21, 2019

CVE-2019-14786 on NVD →

Rank Math SEO <= 1.0.26 - Cross-Site Scripting

high

The Rank Math SEO is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including 1.0.26.

CVSS:
7.2
Affected:
up to 1.0.26
Fixed in:
1.0.27
Disclosed:
Jun 18, 2019

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27

unknown

The Rank Math SEO is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including 1.0.26.

Affected:
up to 1.0.27
Fixed in:
1.0.27
Disclosed:
Jun 18, 2019

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27

unknown

Cross-Site Scripting (XSS) vulnerabilities found in WordPress SEO by Rank Math (versions <= 1.0.26).

Affected:
up to 1.0.27
Fixed in:
1.0.27
Disclosed:
Jun 18, 2019

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27

unknown

The changelog file states &quot;Added some important security fixes&quot;, and various variables can be found being HTML escaped in the code changes.

Affected:
up to 1.0.27
Fixed in:
1.0.27

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.42.2

unknown

Missing access controls on the GET requests to deactivate competitors&#039; plugins. This could allow any authenticated users (such as subscribers) to deactivate the SEO and Sitemap plugins from competitors. The attack could also be performed via CSRF.

Affected:
up to 1.0.42.2
Fixed in:
1.0.42.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database