Rank Math SEO <= 1.0.279 - Authenticated (Author+) Stored Cross-Site Scripting via Post Slug
- ID
- WPSEC-2026-0541
- Plugin
- Rank Math SEO – AI SEO Tools to Dominate SEO Rankings (seo-by-rank-math)
- Affected
- from 1.0.91 before 1.0.280
- Remediation
- Update to 1.0.280 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
- Attack surface
- Rank Math SEO on WPSec AttackSurface
- Fix released
- Published
Description
The Rank Math SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post slugs in all versions up to, and including, 1.0.279. This is due to insufficient output escaping of the redirection source URL in the 'View' link of the Redirections list. When the Redirections module and its 'Auto Post Redirect' option are enabled, changing the slug of a published post creates a redirection from the post's old URL, which is stored in URL-decoded form. Neither option is enabled by default. This makes it possible for authenticated attackers with author-level access and above to inject arbitrary web scripts that execute when an administrator opens the Redirections page.
References
- https://wpsec.com/vuln/WPSEC-2026-0541/
- https://plugins.svn.wordpress.org/seo-by-rank-math/tags/1.0.280/
- https://wordpress.org/plugins/seo-by-rank-math/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS