{
 "id": "WPSEC-2026-0541",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0541/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0541/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0541/index.md",
 "title": "Rank Math SEO <= 1.0.279 - Authenticated (Author+) Stored Cross-Site Scripting via Post Slug",
 "description": "The Rank Math SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post slugs in all versions up to, and including, 1.0.279. This is due to insufficient output escaping of the redirection source URL in the 'View' link of the Redirections list. When the Redirections module and its 'Auto Post Redirect' option are enabled, changing the slug of a published post creates a redirection from the post's old URL, which is stored in URL-decoded form. Neither option is enabled by default. This makes it possible for authenticated attackers with author-level access and above to inject arbitrary web scripts that execute when an administrator opens the Redirections page.",
 "plugin": {
  "slug": "seo-by-rank-math",
  "name": "Rank Math SEO",
  "full_name": "Rank Math SEO – AI SEO Tools to Dominate SEO Rankings",
  "wordpress_org": "https://wordpress.org/plugins/seo-by-rank-math/",
  "advisories_url": "https://wpsec.com/vuln/plugin/seo-by-rank-math/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/seo-by-rank-math"
 },
 "type": "XSS",
 "cwe": [
  "CWE-79"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.9,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "1.0.91",
    "from_inclusive": true,
    "to": "1.0.280",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 1.0.91 before 1.0.280"
  ]
 },
 "introduced_in": "1.0.91",
 "fixed_in": "1.0.280",
 "remediation": "Update to 1.0.280 or later.",
 "fix_released": "2026-10-06T12:43:17+00:00",
 "published": "2026-10-07T12:46:23+00:00",
 "updated": "2026-10-06T16:17:11.759068+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0541/",
  "https://plugins.svn.wordpress.org/seo-by-rank-math/tags/1.0.280/",
  "https://wordpress.org/plugins/seo-by-rank-math/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/seo-by-rank-math",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-07"
 }
}