Description
Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1.
Published: 2025-10-31
Score: 3.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Rank Math SEO plugin contains a missing authorization check that allows an attacker to perform actions that should be restricted to privileged users. The flaw arises from incorrectly configured access control security levels, enabling unauthorized manipulation of plugin settings or data. This could lead to unauthorized modification of SEO metadata, potential defacement, or other unintended changes to site content. The identified weakness corresponds to CWE-862, indicating an authorization bypass vulnerability.

Affected Systems

The vulnerability affects every installation of the Rank Math SEO WordPress plugin with a version up to and including 1.0.252.1. Versions newer than this have reached a safe state after the issue was addressed by the vendor.

Risk and Exploitability

The CVSS score of 3.8 indicates a low severity impact, and the EPSS score of less than 1% suggests the probability of exploitation is very low. The flaw is not listed in CISA’s KEV catalog, so there is no evidence of known widespread exploitation. The likely attack vector is a remote one, where an authenticated or unauthenticated user with access to the WordPress administration panel can trigger the vulnerable functionality. The attack requires web access to the site and the ability to interact with the plugin’s administrative interface; no additional privileges beyond those normally granted to WordPress users are needed because the authorization check is missing.

Generated by OpenCVE AI on April 29, 2026 at 20:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Rank Math SEO to the latest verified version that contains the fix.
  • If an update is not immediately possible, disable the Rank Math SEO plugin or remove it entirely from the site.
  • Restrict access to the plugin’s admin pages to only users with the Administrator role and verify that no other roles have unnecessary permissions.

Generated by OpenCVE AI on April 29, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}

cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Mon, 03 Nov 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Rank Math Seo
Rank Math Seo rank Math Seo
Wordpress
Wordpress wordpress
Vendors & Products Rank Math Seo
Rank Math Seo rank Math Seo
Wordpress
Wordpress wordpress

Fri, 31 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 11:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1.
Title WordPress Rank Math SEO plugin <= 1.0.252.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Rank Math Seo Rank Math Seo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:14.069Z

Reserved: 2025-10-31T11:23:06.888Z

Link: CVE-2025-64350

cve-icon Vulnrichment

Updated: 2025-10-31T17:50:44.686Z

cve-icon NVD

Status : Deferred

Published: 2025-10-31T12:15:35.247

Modified: 2026-04-27T16:16:40.560

Link: CVE-2025-64350

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T20:30:19Z

Weaknesses