Vulnerabilities / Rank Math SEO / WPSEC-2026-0540

Rank Math SEO <= 1.0.279 - Missing Authorization to Unauthenticated SEO Analyzer Results Deletion

Medium 5.3 CWE-862Fixed in 1.0.280
ID
WPSEC-2026-0540
Plugin
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings (seo-by-rank-math)
Affected
from 1.0.31 before 1.0.280
Remediation
Update to 1.0.280 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-862
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
Attack surface
Rank Math SEO on WPSec AttackSurface
Fix released
Published

Description

The Rank Math SEO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the SEO Analyzer's 'clear_results' handler in all versions up to, and including, 1.0.279. The handler ran whenever the SEO Analyzer was loaded, including on every admin-ajax.php request, and checked neither a capability nor a nonce. The SEO Analyzer module is enabled by default. This makes it possible for unauthenticated attackers to delete the site's stored SEO Analyzer results.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0