Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesRank Math SEO

Rank Math SEO vulnerabilities

Rank Math SEO has 21 known vulnerabilities in this database. The most recent published record is dated 2 Sep 2026.

Known vulnerabilities
21
Active installs
4m+
Latest version
1.0.279
Last updated
22 Sep 2026
Most recent
2 Sep 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Sensitive data exposure
CVE-2026-77782
Medium 5.3Before 1.0.277.1Fixed in 1.0.277.12 Sep 2026
Broken access control
CVE-2026-77783
Low 3.7Before 1.0.277Fixed in 1.0.2772 Sep 2026
Broken access control
CVE-2026-77784
Low 2.7Before 1.0.277Fixed in 1.0.2772 Sep 2026
Broken access control
CVE-2026-77785
Low 2.7Before 1.0.277Fixed in 1.0.2772 Sep 2026
Broken access control
CVE-2026-77787
Low 2.7Before 1.0.277Fixed in 1.0.2772 Sep 2026
Broken access control
CVE-2026-77788
Medium 4.9Before 1.0.277Fixed in 1.0.2772 Sep 2026
Broken access control
CVE-2026-77786
Medium 4.9Before 1.0.277Fixed in 1.0.27729 Aug 2026
Broken access control
CVE-2025-12714
Medium 5.3Up to 1.0.271Fixed in a later version (latest 1.0.279)29 May 2026
Cross-site scripting (XSS)
CVE-2024-13227
Medium 6.4Before 1.0.236Fixed in 1.0.23613 Feb 2025
Broken access control
CVE-2024-13229
Medium 4.3Before 1.0.236Fixed in 1.0.23613 Feb 2025
PHP object injection
CVE-2024-9314
High 7.2Before 1.0.229Fixed in 1.0.2295 Oct 2024
Broken access control
CVE-2024-9161
Medium 6.5Before 1.0.229Fixed in 1.0.2295 Oct 2024
Cross-site scripting (XSS)
CVE-2024-4627
Medium 5.4Before 1.0.219Fixed in 1.0.2192 Jul 2024
Cross-site scripting (XSS)
CVE-2024-4617
Medium 6.4Up to 1.0.218Fixed in a later version (latest 1.0.279)16 May 2024
Cross-site scripting (XSS)
CVE-2024-4335
Medium 6.4Before 1.0.218Fixed in 1.0.21814 May 2024
Cross-site scripting (XSS)
CVE-2024-3665
Medium 6.4Before 1.0.217Fixed in 1.0.21723 Apr 2024
Cross-site scripting (XSS)
CVE-2024-2536
Medium 6.4Before 1.0.215Fixed in 1.0.2159 Apr 2024
Server-side request forgery (SSRF)
CVE-2022-36376
Medium 6.8Up to 1.0.95Fixed in a later version (latest 1.0.279)9 Sep 2022
Broken access control
CVE-2020-11514
Critical 9.8Up to 1.0.40.2Fixed in a later version (latest 1.0.279)7 Apr 2020
Open redirect
CVE-2020-11515
Medium 6.1Up to 1.0.40.2Fixed in a later version (latest 1.0.279)7 Apr 2020
Broken access control
CVE-2019-14786
Medium 6.5Before 1.0.27.1Fixed in 1.0.27.115 Aug 2019
Read the published descriptions
CVE-2026-77782, 2 Sep 2026
The Rank Math SEO WordPress plugin before 1.0.277.1 does not check whether a post is password protected before using its content to build publicly generated SEO metadata, allowing unauthenticated users to read the content of password-protected posts. CVE record
CVE-2026-77783, 2 Sep 2026
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front end is publicly viewable, allowing unauthenticated visitors to disclose the schema and associated content of draft, pending, private, scheduled and password-protected posts. CVE record
CVE-2026-77784, 2 Sep 2026
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object being modified before updating its SEO indexing metadata, allowing users with the Author role and above to alter that metadata on content, taxonomy terms and user profiles they do not own, and to remove other users' content from the site's sitemap and search engine index. CVE record
CVE-2026-77785, 2 Sep 2026
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to read the specific post referenced in a request before returning its content and SEO metadata, allowing users with the Author role and above to read the title, body and metadata of other users' non-public posts. CVE record
CVE-2026-77787, 2 Sep 2026
The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied object identifier across object types, allowing users with the Author role and above to modify the SEO metadata of terms they cannot edit and to overwrite the titles of posts belonging to other users. CVE record
CVE-2026-77788, 2 Sep 2026
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs to the object the user was authorised against, allowing users with the Author role and above to overwrite arbitrary post and user metadata, including that belonging to higher-privileged users. CVE record
CVE-2026-77786, 29 Aug 2026
The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires for the settings being changed, allowing users with the Editor role to modify site-wide core WordPress settings that are reserved to administrators. CVE record
CVE-2025-12714, 29 May 2026
The Rank Math SEO - AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the update_site_editor_homepage function in all versions up to, and including, 1.0.271. This makes it possible for unauthenticated attackers to modify several plugin settings including homepage title, meta description, breadcrumbs label, and social media metadata, which can have severe impact on SEO rankings and display malicious content across all site pages where breadcrumbs are used. CVE record
CVE-2024-13227, 13 Feb 2025
The Rank Math SEO - AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Rank Math API in all versions up to, and including, 1.0.235 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-13229, 13 Feb 2025
The Rank Math SEO - AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the update_metadata() function in all versions up to, and including, 1.0.235. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete any schema metadata assigned to any post. CVE record
CVE-2024-9314, 5 Oct 2024
The Rank Math SEO - AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.228 via deserialization of untrusted input 'set_redirections' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. CVE record
CVE-2024-9161, 5 Oct 2024
The Rank Math SEO - AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'update_metadata' function in all versions up to, and including, 1.0.228. This makes it possible for unauthenticated attackers to insert new and update existing metadata beginning with 'rank_math', and delete arbitrary existing user metadata and term metadata. Deleting existing usermeta can cause a loss of access to the administrator dashboard for any registered users, including Administrators. CVE record
CVE-2024-4627, 2 Jul 2024
The Rank Math SEO WordPress plugin before 1.0.219 does not sanitise and escape some of its settings, which could allow users with access to the General Settings (by default admin, however such access can be given to lower roles via the Role Manager feature of the Rank Math SEO WordPress plugin before 1.0.219) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
CVE-2024-4617, 16 May 2024
The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 1.0.218 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-4335, 14 May 2024
The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘textAlign’ parameter in versions up to, and including, 1.0.217 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-3665, 23 Apr 2024
The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's HowTo and FAQ widgets in all versions up to, and including, 1.0.216 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-2536, 9 Apr 2024
The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HowTo block attributes in all versions up to, and including, 1.0.214 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2022-36376, 9 Sep 2022
Server-Side Request Forgery (SSRF) vulnerability in Rank Math SEO plugin <= 1.0.95 at WordPress. CVE record
CVE-2020-11514, 7 Apr 2020
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint. CVE record
CVE-2020-11515, 7 Apr 2020
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint. In other words, this is not an "Open Redirect" issue; instead, it allows the attacker to create a new URI with an arbitrary name (e.g., the /exampleredirect URI). CVE record
CVE-2019-14786, 15 Aug 2019
The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb parameter. CVE record

What to do if you run Rank Math SEO

If you run Rank Math SEO, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Rank Math SEO vulnerabilities

Free. We email you when a new vulnerability is published for Rank Math SEO, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support