Description
Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
Published: 2026-08-28
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows remote actors to run arbitrary PHP code on a WordPress site that hosts the Rank Math SEO plugin. By exploiting the flaw, an attacker can execute arbitrary PHP code within the WordPress environment, potentially compromising the site's application layer. The weakness is classified as CWE-502, an unsafe deserialization issue.

Affected Systems

WordPress installations that have Rank Math SEO plugin version 1.0.276 or older. The issue is limited to the plugin's code base and does not affect other components of WordPress.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity. No EPSS score is available, but the lack of an entry in the CISA KEV catalog suggests no public exploits yet. Attackers can potentially exploit the issue remotely from any network that can reach the WordPress site, unless mitigated by network firewall or robust authentication. Based on the description, it is inferred that the attack vector is remote via HTTP(s) traffic that triggers the deserialization routine.

Generated by OpenCVE AI on August 28, 2026 at 17:27 UTC.

Remediation

Vendor Solution

Update the WordPress Rank Math SEO Plugin to the latest available version (at least 1.0.277).


OpenCVE Recommended Actions

  • Update the Rank Math SEO Plugin to version 1.0.277 or later.
  • Remove any older versions of Rank Math SEO from the plugins directory to prevent accidental activation.
  • Harden WordPress file permissions by ensuring that plugin directories are not world‑executable and that PHP execution is disabled in uploads.

Generated by OpenCVE AI on August 28, 2026 at 17:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Rank Math Seo
Rank Math Seo rank Math Seo
Wordpress
Wordpress wordpress
Vendors & Products Rank Math Seo
Rank Math Seo rank Math Seo
Wordpress
Wordpress wordpress

Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
Title WordPress Rank Math SEO plugin <= 1.0.276 - Remote Code Execution (RCE) vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Rank Math Seo Rank Math Seo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-28T16:03:21.825Z

Reserved: 2026-08-27T12:22:09.412Z

Link: CVE-2026-81757

cve-icon Vulnrichment

Updated: 2026-08-28T16:03:18.379Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T16:18:30.083

Modified: 2026-08-28T20:20:12.630

Link: CVE-2026-81757

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T17:30:08Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data