Vulnerabilities / Rank Math SEO / WPSEC-2026-0541

Rank Math SEO <= 1.0.279 - Authenticated (Author+) Stored Cross-Site Scripting via Post Slug

Medium 4.9 CWE-79Fixed in 1.0.280
ID
WPSEC-2026-0541
Plugin
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings (seo-by-rank-math)
Affected
from 1.0.91 before 1.0.280
Remediation
Update to 1.0.280 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
Attack surface
Rank Math SEO on WPSec AttackSurface
Fix released
Published

Description

The Rank Math SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post slugs in all versions up to, and including, 1.0.279. This is due to insufficient output escaping of the redirection source URL in the 'View' link of the Redirections list. When the Redirections module and its 'Auto Post Redirect' option are enabled, changing the slug of a published post creates a redirection from the post's old URL, which is stored in URL-decoded form. Neither option is enabled by default. This makes it possible for authenticated attackers with author-level access and above to inject arbitrary web scripts that execute when an administrator opens the Redirections page.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0