Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.274.1 - Unauthenticated Stored Cross-Site Scripting
high
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.274.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...
- CVSS:
- 7.2
- Affected:
- up to 1.0.274.1
- Fixed in:
- 1.0.275
- Disclosed:
- Jul 31, 2026
CVE-2026-66702 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.271 - Missing Authorization
medium
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.0.271. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unautho...
- CVSS:
- 4.3
- Affected:
- up to 1.0.271
- Fixed in:
- 1.0.271.1
- Disclosed:
- Jun 3, 2026
CVE-2026-34892 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.271 - Missing Authorization to Unauthenticated Homepage Settings Modification
medium
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the update_site_editor_homepage function in all versions up to, and including, 1.0.271. This makes it possible for unauthenticated attackers to modify several plugin s...
- CVSS:
- 5.3
- Affected:
- up to 1.0.271
- Fixed in:
- 1.0.271.1
- Disclosed:
- May 28, 2026
CVE-2025-12714 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] <= 1.0.252.1 (unfixed)
unknown
[en] Insertion of Sensitive Information Into Sent Data vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Retrieve Embedded Sensitive Data.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1.
- Affected:
- up to 1.0.252.1
- Fix:
- No patched version reported
- Disclosed:
- Oct 31, 2025
CVE-2025-64351 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] <= 1.0.252.1 (unfixed)
unknown
[en] Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1.
- Affected:
- up to 1.0.252.1
- Fix:
- No patched version reported
- Disclosed:
- Oct 31, 2025
CVE-2025-64350 on NVD →
Rank Math SEO <= 1.0.252.1 - Authenticated (Subscriber+) Information Exposure
medium
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.252.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 1.0.252.1
- Fixed in:
- 1.0.253
- Disclosed:
- Sep 11, 2025
CVE-2025-64351 on NVD →
Rank Math SEO <= 1.0.252.1 - Missing Authorization
medium
The Rank Math SEO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the track() function in versions up to, and including, 1.0.252.1. This makes it possible for authenticated attackers, with author-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.0.252.1
- Fixed in:
- 1.0.253
- Disclosed:
- Sep 11, 2025
CVE-2025-64350 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.236
unknown
[en] The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Rank Math API in all versions up to, and including, 1.0.235 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...
- Affected:
- up to 1.0.236
- Fixed in:
- 1.0.236
- Disclosed:
- Feb 13, 2025
CVE-2024-13227 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.236
unknown
[en] The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the update_metadata() function in all versions up to, and including, 1.0.235. This makes it possible for authenticated attackers, with Contributor-level acc...
- Affected:
- up to 1.0.236
- Fixed in:
- 1.0.236
- Disclosed:
- Feb 13, 2025
CVE-2024-13229 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.235 - Authenticated (Contributor+) Stored Cross-Site Scripting via Rank Math API
medium
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Rank Math API in all versions up to, and including, 1.0.235 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...
- CVSS:
- 6.4
- Affected:
- up to 1.0.235
- Fixed in:
- 1.0.236
- Disclosed:
- Feb 12, 2025
CVE-2024-13227 on NVD →
Rank Math SEO <= 1.0.235 - Missing Authorization to Authenticated (Contributor+) Arbitrary Schema Deletion
medium
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the update_metadata() function in all versions up to, and including, 1.0.235. This makes it possible for authenticated attackers, with Contributor-level access a...
- CVSS:
- 4.3
- Affected:
- up to 1.0.235
- Fixed in:
- 1.0.236
- Disclosed:
- Feb 12, 2025
CVE-2024-13229 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.232
unknown
[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Rank Math SEO allows Code Injection.This issue affects Rank Math SEO: from n/a through 1.0.231.
- Affected:
- up to 1.0.232
- Fixed in:
- 1.0.232
- Disclosed:
- Nov 28, 2024
CVE-2024-11620 on NVD →
Rank Math SEO <= 1.0.231 - .htaccess File Manipulation to Remote Code Execution
high
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.231. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.
- CVSS:
- 7.2
- Affected:
- up to 1.0.231
- Fixed in:
- 1.0.232
- Disclosed:
- Nov 22, 2024
CVE-2024-11620 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.229
unknown
[en] The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'update_metadata' function in all versions up to, and including, 1.0.228. This makes it possible for unauthenticated attackers to inser...
- Affected:
- up to 1.0.229
- Fixed in:
- 1.0.229
- Disclosed:
- Oct 5, 2024
CVE-2024-9161 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.229
unknown
[en] The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.228 via deserialization of untrusted input 'set_redirections' function. This makes it possible for authenticated attackers, with Administrator-level access...
- Affected:
- up to 1.0.229
- Fixed in:
- 1.0.229
- Disclosed:
- Oct 5, 2024
CVE-2024-9314 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Authenticated (Administrator+) PHP Object Injection
high
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.228 via deserialization of untrusted input 'set_redirections' function. This makes it possible for authenticated attackers, with Administrator-level access and a...
- CVSS:
- 7.2
- Affected:
- up to 1.0.228
- Fixed in:
- 1.0.229
- Disclosed:
- Oct 4, 2024
CVE-2024-9314 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Missing Authorization to Unauthenticated User and Term Metadata Insert, Update, and Delete
medium
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'update_metadata' function in all versions up to, and including, 1.0.228. This makes it possible for unauthenticated attackers to insert new...
- CVSS:
- 6.5
- Affected:
- up to 1.0.228
- Fixed in:
- 1.0.229
- Disclosed:
- Oct 4, 2024
CVE-2024-9161 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.219
unknown
[en] The Rank Math SEO WordPress plugin before 1.0.219 does not sanitise and escape some of its settings, which could allow users with access to the General Settings (by default admin, however such access can be given to lower roles via the Role Manager feature of the Rank Math SEO WordPress plugin before 1.0.219) to...
- Affected:
- up to 1.0.219
- Fixed in:
- 1.0.219
- Disclosed:
- Jul 2, 2024
CVE-2024-4627 on NVD →
Rank Math SEO <= 1.0.218 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.218 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...
- CVSS:
- 4.4
- Affected:
- up to 1.0.218
- Fixed in:
- 1.0.219
- Disclosed:
- Jun 11, 2024
CVE-2024-4627 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.119.1
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rank Math Rank Math SEO allows Path Traversal.This issue affects Rank Math SEO: from n/a through 1.0.107.2.
- Affected:
- up to 1.0.119.1
- Fixed in:
- 1.0.119.1
- Disclosed:
- May 17, 2024
CVE-2023-23888 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.219
unknown
[en] The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 1.0.218 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissi...
- Affected:
- up to 1.0.219
- Fixed in:
- 1.0.219
- Disclosed:
- May 16, 2024
CVE-2024-4617 on NVD →
Rank Math SEO with AI Best SEO Tools <= 1.0.218 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 1.0.218 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions a...
- CVSS:
- 6.4
- Affected:
- up to 1.0.218
- Fixed in:
- 1.0.219-beta
- Disclosed:
- May 15, 2024
CVE-2024-4617 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.218
unknown
[en] The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘textAlign’ parameter in versions up to, and including, 1.0.217 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level p...
- Affected:
- up to 1.0.218
- Fixed in:
- 1.0.218
- Disclosed:
- May 9, 2024
CVE-2024-4335 on NVD →
Rank Math SEO with AI Best SEO Tools <= 1.0.217 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘textAlign’ parameter in versions up to, and including, 1.0.217 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permis...
- CVSS:
- 6.4
- Affected:
- up to 1.0.217
- Fixed in:
- 1.0.218
- Disclosed:
- May 3, 2024
CVE-2024-4335 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.217
unknown
[en] The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's HowTo and FAQ widgets in all versions up to, and including, 1.0.216 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- Affected:
- up to 1.0.217
- Fixed in:
- 1.0.217
- Disclosed:
- Apr 23, 2024
CVE-2024-3665 on NVD →
Rank Math SEO with AI SEO Tools <= 1.0.216 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleWrapper'
medium
The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's HowTo and FAQ widgets in all versions up to, and including, 1.0.216 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta...
- CVSS:
- 6.4
- Affected:
- up to 1.0.216
- Fixed in:
- 1.0.217
- Disclosed:
- Apr 22, 2024
CVE-2024-3665 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.215
unknown
[en] The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HowTo block attributes in all versions up to, and including, 1.0.214 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke...
- Affected:
- up to 1.0.215
- Fixed in:
- 1.0.215
- Disclosed:
- Apr 9, 2024
CVE-2024-2536 on NVD →
Rank Math SEO with AI SEO Tools <= 1.0.214 - Authenticated(Contributor+) Stored Cross-Site Scripting via HowTo block attributes
medium
The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HowTo block attributes in all versions up to, and including, 1.0.214 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w...
- CVSS:
- 6.4
- Affected:
- up to 1.0.214
- Fixed in:
- 1.0.215
- Disclosed:
- Mar 21, 2024
CVE-2024-2536 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.119.1
unknown
[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Rank Math SEO plugin <= 1.0.119 versions.
- Affected:
- up to 1.0.119.1
- Fixed in:
- 1.0.119.1
- Disclosed:
- Aug 5, 2023
CVE-2023-32600 on NVD →
Rank Math SEO <= 1.0.119 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Rank Math SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.0.119 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level an...
- CVSS:
- 6.4
- Affected:
- up to 1.0.119.1
- Fixed in:
- 1.0.119.1
- Disclosed:
- Jul 17, 2023
CVE-2023-32600 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.119.1
unknown
The Rank Math SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.0.119 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level an...
- Affected:
- up to 1.0.119.1
- Fixed in:
- 1.0.119.1
- Disclosed:
- Jul 17, 2023
RankMath SEO <= 1.0.107.2 - Authenticated (Contributor+) Local File Inclusion
medium
The RankMath SEO plugin for WordPress is vulnerable to Local File Inclusion via the 'update_schemas' and 'get_snippet_content' functions. This allows authenticated attackers, with contributor-level permissions and above, to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in...
- CVSS:
- 6.5
- Affected:
- up to 1.0.107.2
- Fixed in:
- 1.0.107.3
- Disclosed:
- Jan 30, 2023
CVE-2023-23888 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.107.3
unknown
The RankMath SEO plugin for WordPress is vulnerable to Local File Inclusion via the 'update_schemas' and 'get_snippet_content' functions. This allows authenticated attackers, with contributor-level permissions and above, to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in...
- Affected:
- up to 1.0.107.3
- Fixed in:
- 1.0.107.3
- Disclosed:
- Jan 30, 2023
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.95.1
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Rank Math SEO plugin <= 1.0.95 at WordPress.
- Affected:
- up to 1.0.95.1
- Fixed in:
- 1.0.95.1
- Disclosed:
- Sep 9, 2022
CVE-2022-36376 on NVD →
Rank Math SEO <= 1.0.95 - Server-Side Request Forgery
medium
The Rank Math SEO plugin for WordPress is vulnerable to Server Side Request Forgery in versions up to, and including 1.0.95, due to insufficient user input validation.
- CVSS:
- 5.4
- Affected:
- up to 1.0.95
- Fixed in:
- 1.0.95.1
- Disclosed:
- Aug 12, 2022
CVE-2022-36376 on NVD →
Rank Math SEO <= 1.0.42.1 - Missing Authorization
medium
The Rank Math SEO plugin for WordPress is vulnerable to authorization bypass due to missing access controls on its "disable competitor plugins" functionality in versions up to, and including, 1.0.42.1. This makes it possible for subscriber-level attackers to disable other SEO or sitemap plugins on the site.
- CVSS:
- 5.4
- Affected:
- up to 1.0.42.2
- Fixed in:
- 1.0.42.2
- Disclosed:
- Apr 18, 2020
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.42.2
unknown
The Rank Math SEO plugin for WordPress is vulnerable to authorization bypass due to missing access controls on its "disable competitor plugins" functionality in versions up to, and including, 1.0.42.1. This makes it possible for subscriber-level attackers to disable other SEO or sitemap plugins on the site.
- Affected:
- up to 1.0.42.2
- Fixed in:
- 1.0.42.2
- Disclosed:
- Apr 18, 2020
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.0.41
unknown
[en] The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint. In other words, this is not an "Open Redirect" issue; instead, it allows the attacker to create a...
- Affected:
- up to 1.0.0.41
- Fixed in:
- 1.0.0.41
- Disclosed:
- Apr 7, 2020
CVE-2020-11515 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.0.41
unknown
[en] The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.
- Affected:
- up to 1.0.0.41
- Fixed in:
- 1.0.0.41
- Disclosed:
- Apr 7, 2020
CVE-2020-11514 on NVD →
Rank Math SEO <= 1.0.40.2 - Privilege Escalation via Unprotected REST API Endpoint
critical
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.
- CVSS:
- 9.8
- Affected:
- up to 1.0.41
- Fixed in:
- 1.0.41
- Disclosed:
- Mar 25, 2020
CVE-2020-11514 on NVD →
Rank Math SEO <= 1.0.40.2 - Redirect Creation via Unprotected REST API Endpoint
high
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint. In other words, this is not an "Open Redirect" issue; instead, it allows the attacker to create a new...
- CVSS:
- 7.4
- Affected:
- up to 1.0.40
- Fixed in:
- 1.0.41
- Disclosed:
- Mar 25, 2020
CVE-2020-11515 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27.1
unknown
[en] The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb parameter.
- Affected:
- up to 1.0.27.1
- Fixed in:
- 1.0.27.1
- Disclosed:
- Aug 15, 2019
CVE-2019-14786 on NVD →
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27.1
unknown
Authenticated Settings Reset vulnerability found in WordPress SEO By Rank Math plugin (versions <= 1.0.27).
- Affected:
- up to 1.0.27.1
- Fixed in:
- 1.0.27.1
- Disclosed:
- Jun 25, 2019
Rank Math SEO <= 1.0.27 - Authenticated Settings Reset via reset-cmb Parameter
medium
The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb parameter.
- CVSS:
- 6.5
- Affected:
- up to 1.0.27.1
- Fixed in:
- 1.0.27.1
- Disclosed:
- Jun 21, 2019
CVE-2019-14786 on NVD →
Rank Math SEO <= 1.0.26 - Cross-Site Scripting
high
The Rank Math SEO is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including 1.0.26.
- CVSS:
- 7.2
- Affected:
- up to 1.0.26
- Fixed in:
- 1.0.27
- Disclosed:
- Jun 18, 2019
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27
unknown
The Rank Math SEO is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including 1.0.26.
- Affected:
- up to 1.0.27
- Fixed in:
- 1.0.27
- Disclosed:
- Jun 18, 2019
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27
unknown
Cross-Site Scripting (XSS) vulnerabilities found in WordPress SEO by Rank Math (versions <= 1.0.26).
- Affected:
- up to 1.0.27
- Fixed in:
- 1.0.27
- Disclosed:
- Jun 18, 2019
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27
unknown
The changelog file states "Added some important security fixes", and various variables can be found being HTML escaped in the code changes.
- Affected:
- up to 1.0.27
- Fixed in:
- 1.0.27
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.42.2
unknown
Missing access controls on the GET requests to deactivate competitors' plugins. This could allow any authenticated users (such as subscribers) to deactivate the SEO and Sitemap plugins from competitors. The attack could also be performed via CSRF.
- Affected:
- up to 1.0.42.2
- Fixed in:
- 1.0.42.2