WordPress security by component
Rank Math SEO
Plugin description
Rank Math SEO provides WordPress search engine optimization tools for managing metadata, sitemaps, schema, redirects, and content analysis.
Rank Math SEO (seo-by-rank-math) is a WordPress plugin with 26 published CVE records in this archive. The latest tracked vulnerability was published Sep 02, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
seo-by-rank-mathLatest vulnerability
CVE-2026-77788: Rank Math permits Author-level arbitrary metadata overwrite
Rank Math SEO 1.0.48 through 1.0.276 does not verify that a metadata row belongs to the object against which authorization was checked. An Author or higher can overwrite arbitrary post and user metadata, including metadata belonging to higher-privileged users.
| Safe version |
|
||
|---|---|---|---|
| Sep 02, 2026 |
CVE-2026-77788
Rank Math permits Author-level arbitrary metadata overwrite
Rank Math SEO 1.0.48 through 1.0.276 does not verify that a metadata row belongs to the object against which authorization was checked. An Author or higher can overwrite arbitrary post and user metadata, including metadata belonging to higher-privileged users.
|
1.0.277 |
CVE4.9
NVDPending
|
| Sep 02, 2026 |
CVE-2026-77787
Rank Math permits Author-level cross-object SEO changes
Rank Math SEO 1.0.255 through 1.0.276 omits a capability check for bulk metadata updates targeting taxonomy terms and reuses the supplied object ID across object types. An Author or higher can modify SEO metadata for terms they cannot edit and overwrite titles of posts owned by other users.
|
1.0.277 |
CVE2.7
NVDPending
|
| Sep 02, 2026 |
CVE-2026-77785
Rank Math exposes other users' non-public posts to Authors
Rank Math SEO 1.0.272 through 1.0.276 does not verify permission to read the specific post referenced by a request. An Author or higher can retrieve another user's draft, pending, or private post title, body, and SEO metadata.
|
1.0.277 |
CVE2.7
NVDPending
|
| Sep 02, 2026 |
CVE-2026-77784
Rank Math permits Author-level indexing changes across unowned objects
Rank Math SEO before 1.0.277 does not verify permission to edit the object whose indexing metadata is updated. An Author or higher can alter SEO indexing data for content, taxonomy terms, and user profiles they do not own, including removing other users' content from the sitemap and search-engine index.
|
1.0.277 |
CVE2.7
NVDPending
|
| Sep 02, 2026 |
CVE-2026-77783
Rank Math exposes schema and content from non-public posts
Rank Math SEO 1.0.48 through 1.0.276 does not verify that the post whose schema it renders is publicly viewable. An unauthenticated visitor can disclose schema and associated content from draft, pending, private, scheduled, and password-protected posts.
|
1.0.277 |
CVE3.7
NVDPending
|
| Sep 02, 2026 |
CVE-2026-77782
Rank Math exposes password-protected post content
Rank Math SEO before 1.0.277.1 uses password-protected post content to build publicly generated SEO metadata without checking the post's protection state. An unauthenticated visitor can read the protected content.
|
1.0.277.1 |
CVE5.3
NVDPending
|
| Aug 29, 2026 |
CVE-2026-77786
Rank Math SEO Editors can change administrator-only WordPress settings
Rank Math SEO from 1.0.271 through 1.0.276 does not verify that a user requesting an automated SEO fix holds the capability required for each affected setting. An Editor can modify site-wide core WordPress settings reserved for Administrators.
|
1.0.277 |
CVE4.9
NVDPending
|
| Aug 28, 2026 |
CVE-2026-81757
Rank Math SEO permits Author-level remote code execution
Rank Math SEO through 1.0.276 exposes a code-execution path to authenticated Authors. Successful exploitation runs attacker-controlled code in the WordPress server context and can compromise site data, files and availability.
|
1.0.277 |
CVE7.2
NVDPending
|
| Aug 06, 2026 |
CVE-2026-66702
Rank Math SEO permits unauthenticated cross-site scripting
An unauthenticated visitor can submit attacker-controlled script content that Rank Math SEO 1.0.274.1 and earlier renders without sufficient output encoding. A victim must view the affected output for script to run under the site's origin.
|
1.0.275 |
CVE7.1
NVDPending
|
| Jun 15, 2026 |
CVE-2026-34892
Rank Math SEO: Broken access control
Rank Math SEO is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 1.0.271.
|
1.0.271.1 |
CVE6.5
NVDPending
|
| May 29, 2026 |
CVE-2025-12714
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings: A security weakness
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.0.271.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Oct 31, 2025 |
CVE-2025-64351
Rank Math SEO: A security weakness
Rank Math SEO is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Oct 31, 2025 |
CVE-2025-64350
Rank Math SEO: A security weakness
Rank Math SEO is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE3.8
NVDPending
|
| Feb 13, 2025 |
CVE-2024-13229
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings: A security weakness
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Feb 13, 2025 |
CVE-2024-13227
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings: Cross-site scripting
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Nov 28, 2024 |
CVE-2024-11620
Rank Math SEO: Code execution
Rank Math SEO is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Oct 05, 2024 |
CVE-2024-9314
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings: Code execution
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings is affected by code execution. Exploitation requires an authenticated administrator account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Oct 05, 2024 |
CVE-2024-9161
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings: A security weakness
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| May 17, 2024 |
CVE-2023-23888
Rank Math SEO: Filesystem traversal
Rank Math SEO is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.6
NVD8.8
|
| May 16, 2024 |
CVE-2024-4617
Rank Math SEO with AI Best SEO Tools: Cross-site scripting
Rank Math SEO with AI Best SEO Tools is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| May 14, 2024 |
CVE-2024-4335
Rank Math SEO with AI Best SEO Tools: Cross-site scripting
Rank Math SEO with AI Best SEO Tools is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 23, 2024 |
CVE-2024-3665
Rank Math SEO with AI SEO Tools: Cross-site scripting
Rank Math SEO with AI SEO Tools is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Aug 06, 2023 |
CVE-2023-32600
Seo By Rank Math: Cross-site scripting
Seo By Rank Math is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Sep 09, 2022 |
CVE-2022-36376
Seo By Rank Math: Server-side request forgery
Seo By Rank Math is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE6.8
NVD9.8
|
| Apr 07, 2020 |
CVE-2020-11515
Seo By Rank Math: An open redirect
Seo By Rank Math is affected by an open redirect. The vulnerable path is reachable without authentication. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Apr 07, 2020 |
CVE-2020-11514
Seo By Rank Math: A security weakness
Seo By Rank Math is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD9.8
|