Description
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
Published: 2026-08-06
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to inject arbitrary JavaScript through input fields in the Rank Math SEO plugin, leading to client‑side code execution in the context of any user who visits the affected page. If exploited, an attacker could deface the site, steal stored sessions, or redirect users to malicious sites.

Affected Systems

WordPress installations that include the Rank Math SEO plugin, specifically versions up through and including 1.0.274.1. Any site using this plugin version is potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity and the vulnerability is publicly reachable without authentication, so it is easy for an attacker to craft a malicious payload and deliver it via the plugin’s public interface. EPSS data is not available, but the lack of a CISA KEV listing does not reduce the risk; attackers could still discover the vulnerability through normal scan activity. Exploitation generally involves submitting a crafted form or URL parameter that the plugin does not properly sanitize, resulting in script execution.

Generated by OpenCVE AI on August 6, 2026 at 16:19 UTC.

Remediation

Vendor Solution

Update the WordPress Rank Math SEO Plugin to the latest available version (at least 1.0.275).


OpenCVE Recommended Actions

  • Update the Rank Math SEO plugin to version 1.0.275 or newer, which removes the input validation flaw identified as CWE‑79.
  • If an immediate update is not possible, deactivate the Rank Math SEO plugin or permanently remove URLs that allow unauthenticated input until a patch is applied.
  • Deploy a web application firewall rule that blocks or sanitizes suspicious JavaScript payloads targeting the plugin’s input fields before reaching the application.

Generated by OpenCVE AI on August 6, 2026 at 16:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Rank Math Seo
Rank Math Seo rank Math Seo
Wordpress
Wordpress wordpress
Vendors & Products Rank Math Seo
Rank Math Seo rank Math Seo
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
Title WordPress Rank Math SEO plugin <= 1.0.274.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Rank Math Seo Rank Math Seo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T16:14:24.231Z

Reserved: 2026-07-27T14:01:09.905Z

Link: CVE-2026-66702

cve-icon Vulnrichment

Updated: 2026-08-06T16:13:55.486Z

cve-icon NVD

Status : Deferred

Published: 2026-08-06T15:17:23.117

Modified: 2026-08-12T20:58:37.847

Link: CVE-2026-66702

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T16:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')