Description
Insertion of Sensitive Information Into Sent Data vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Retrieve Embedded Sensitive Data.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1.
Published: 2025-10-31
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from the Rank Math SEO WordPress plugin inserting sensitive information into outbound data, enabling attackers to retrieve embedded sensitive data such as configuration settings or internal credentials. The flaw results in data leakage that could expose confidential information about the website or its administrators, potentially allowing an attacker to gain insights into backend operations. The impact is limited to confidentiality loss rather than authorization or availability disruption, but the exposure of sensitive data can facilitate further attacks.

Affected Systems

The Rank Math SEO plugin versions earlier than or equal to 1.0.252.1 on WordPress sites are affected. This includes any installation of the Rank Math SEO plugin up to that revision, regardless of the WordPress core version. Administrators should verify the exact plugin version and consider this scope for remediation.

Risk and Exploitability

The CVSS score of 4.3 indicates a medium severity vulnerability. The EPSS score of less than 1% suggests that the likelihood of exploitation is currently very low. The issue is not listed in the CISA KEV catalog, further reducing the risk of widespread exploitation. Attacks likely would occur by exploiting the plugin’s handling of outgoing data; an attacker would need to interact with the plugin or exploit an existing compromise of the WordPress site to trigger the data leakage. No additional prerequisites are stated in the available information.

Generated by OpenCVE AI on April 29, 2026 at 12:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Rank Math SEO plugin to the latest available version, which includes the fix for the sensitive data exposure flaw.
  • If an immediate update is not possible, disable the Rank Math SEO plugin until the patch is applied to prevent the data leakage from occurring.
  • Restrict access to the plugin’s settings and diagnostic interfaces to administrators only, minimizing the surface for potential exploitation of the vulnerability.

Generated by OpenCVE AI on April 29, 2026 at 12:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Mon, 03 Nov 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Rank Math Seo
Rank Math Seo rank Math Seo
Wordpress
Wordpress wordpress
Vendors & Products Rank Math Seo
Rank Math Seo rank Math Seo
Wordpress
Wordpress wordpress

Fri, 31 Oct 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 11:45:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Retrieve Embedded Sensitive Data.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1.
Title WordPress Rank Math SEO plugin <= 1.0.252.1 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References

Subscriptions

Rank Math Seo Rank Math Seo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T18:30:11.716Z

Reserved: 2025-10-31T11:23:06.889Z

Link: CVE-2025-64351

cve-icon Vulnrichment

Updated: 2025-10-31T18:54:35.812Z

cve-icon NVD

Status : Deferred

Published: 2025-10-31T12:15:35.390

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-64351

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T12:45:11Z

Weaknesses