Executive brief
Rank Math SEO is a widely-used WordPress plugin that provides search engine optimization features including content analysis and schema markup. An unauthenticated attacker can inject malicious JavaScript code into the plugin that executes in the browsers of website visitors, potentially stealing sensitive data, session cookies, or hijacking user accounts without requiring any special privileges or authentication.
Technical details
This is a reflected or stored cross-site scripting (XSS) vulnerability in Rank Math SEO plugin versions up to 1.0.274.1 that allows unauthenticated attackers to inject arbitrary JavaScript. The vulnerability requires user interaction (such as clicking a malicious link or visiting a crafted page) to execute, but once triggered, the injected script runs in the context of the affected website with the victim's privileges. Attackers can leverage this to steal authentication tokens, harvest visitor data, deface content, or perform actions on behalf of compromised users. The vulnerability has been patched in version 1.0.275 and later; users should update immediately.
Affected products
- Rank Math SEO <=1.0.274.1
Timeline
- 2026-07-31: disclosed: Published by Patchstack
- 2026-07-31: patched: Fix available in version 1.0.275 and later