Impact
The vulnerability allows an unauthenticated attacker to inject arbitrary JavaScript through input fields in the Rank Math SEO plugin, leading to client‑side code execution in the context of any user who visits the affected page. If exploited, an attacker could deface the site, steal stored sessions, or redirect users to malicious sites.
Affected Systems
WordPress installations that include the Rank Math SEO plugin, specifically versions up through and including 1.0.274.1. Any site using this plugin version is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity and the vulnerability is publicly reachable without authentication, so it is easy for an attacker to craft a malicious payload and deliver it via the plugin’s public interface. EPSS data is not available, but the lack of a CISA KEV listing does not reduce the risk; attackers could still discover the vulnerability through normal scan activity. Exploitation generally involves submitting a crafted form or URL parameter that the plugin does not properly sanitize, resulting in script execution.
OpenCVE Enrichment