Junglewise Threat Intelligence

CVE-2026-66702: Rank Math SEO unauthenticated cross-site scripting (XSS)

CVE-2026-66702 · Severity: high · CVSS 7.1 · Published 2026-08-06

Technologies: Rank Math SEO. Vendors: Rank Math.

Executive brief

Rank Math SEO is a widely-used WordPress plugin that provides search engine optimization features including content analysis and schema markup. An unauthenticated attacker can inject malicious JavaScript code into the plugin that executes in the browsers of website visitors, potentially stealing sensitive data, session cookies, or hijacking user accounts without requiring any special privileges or authentication.

Technical details

This is a reflected or stored cross-site scripting (XSS) vulnerability in Rank Math SEO plugin versions up to 1.0.274.1 that allows unauthenticated attackers to inject arbitrary JavaScript. The vulnerability requires user interaction (such as clicking a malicious link or visiting a crafted page) to execute, but once triggered, the injected script runs in the context of the affected website with the victim's privileges. Attackers can leverage this to steal authentication tokens, harvest visitor data, deface content, or perform actions on behalf of compromised users. The vulnerability has been patched in version 1.0.275 and later; users should update immediately.

Affected products

  • Rank Math SEO <=1.0.274.1

Timeline

  • 2026-07-31: disclosed: Published by Patchstack
  • 2026-07-31: patched: Fix available in version 1.0.275 and later

References