Junglewise Threat Intelligence

CVE-2026-34892: Rank Math SEO broken access control in WordPress plugin

CVE-2026-34892 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Technologies: Rank Math SEO. Vendors: Rank Math.

Executive brief

Rank Math SEO, a popular WordPress plugin used to optimize website search engine rankings, contains a security flaw that allows low-privileged users to perform unauthorized actions. An individual with a basic 'Subscriber' account could bypass security checks to modify settings or data they should not have access to. This could lead to unauthorized changes to the website's SEO configuration or content management.

Technical details

A broken access control vulnerability exists in the Rank Math SEO plugin for WordPress due to missing authorization checks (CWE-862). The flaw allows an authenticated attacker with Subscriber-level privileges to execute functions or modify settings that should be restricted to higher-privileged roles like Administrators. The vulnerability is reachable over the network and does not require user interaction. The issue is resolved in version 1.0.271.1, which introduces proper permission validation for the affected components.

Affected products

  • Rank Math Rank Math SEO <= 1.0.271

Timeline

  • 2026-03-18: other: Reported by Jakub Herman
  • 2026-06-03: patched: Version 1.0.271.1 released
  • 2026-06-15: advisory: NVD and Patchstack advisory published

References

Related threats