Junglewise Threat Intelligence

CVE-2026-81757: Rank Math SEO remote code execution

CVE-2026-81757 · Severity: high · CVSS 7.2 · Published 2026-08-28

Technologies: Rank Math SEO. Vendors: Rank Math.

Executive brief

Rank Math SEO is a popular WordPress plugin used to optimize websites for search engines. A vulnerability in versions up to 1.0.276 allows authenticated users with author-level permissions to execute arbitrary code on the web server, enabling attackers to take complete control of affected websites.

Technical details

The vulnerability is a remote code execution (RCE) flaw classified as an injection attack in Rank Math SEO plugin versions 1.0.276 and earlier. The vulnerability requires author-level privileges to exploit, meaning an attacker must either compromise a legitimate author account or trick an author into performing a malicious action. The attack vector is network-based and allows unauthenticated attackers to run arbitrary commands on the affected server. The vulnerability has been patched in version 1.0.277.

Affected products

  • Rank Math SEO <= 1.0.276

Timeline

  • 2026-08-27: disclosed: Published by Patchstack
  • 2026-08-27: patched: Fixed in version 1.0.277

References