Executive brief
The Rank Math SEO plugin for WordPress, which helps websites manage search engine optimization, contains a security flaw that allows unauthorized individuals to change site settings. An attacker could modify the website's homepage title, meta descriptions, and social media preview information without needing a password. This could lead to significant damage to search engine rankings or the display of misleading and malicious content to site visitors.
Technical details
The vulnerability is classified as Missing Authorization (CWE-862) within the update_site_editor_homepage function of the Rank Math SEO plugin. Due to a lack of capability checks in the REST API implementation, unauthenticated attackers can send crafted requests to modify plugin settings including the homepage title, meta description, breadcrumbs label, and social media metadata. This issue affects all versions up to and including 1.0.271. A patch has been released in subsequent versions to implement proper authorization checks.
Affected products
- Rank Math Rank Math SEO – AI SEO Tools to Dominate SEO Rankings Up to, and including, 1.0.271
Timeline
- 2026-05-29: disclosed
- 2026-05-29: advisory
References
- https://plugins.trac.wordpress.org/browser/seo-by-rank-math/trunk/includes/rest/class-rest-helper.php
- https://plugins.trac.wordpress.org/browser/seo-by-rank-math/trunk/includes/rest/class-shared.php
- https://plugins.trac.wordpress.org/browser/seo-by-rank-math/trunk/includes/rest/class-shared.php
- https://plugins.trac.wordpress.org/browser/seo-by-rank-math/trunk/includes/rest/class-shared.php
- https://plugins.trac.wordpress.org/changeset/3552223/seo-by-rank-math/trunk/includes/rest/class-rest-helper.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/dd072774-6f85-42de-a9d4-6826703ad839?source=cve