Executive brief
Rank Math SEO is a popular WordPress plugin used to optimize websites for search engines. A vulnerability in versions up to 1.0.276 allows authenticated users with author-level permissions to execute arbitrary code on the web server, enabling attackers to take complete control of affected websites.
Technical details
The vulnerability is a remote code execution (RCE) flaw classified as an injection attack in Rank Math SEO plugin versions 1.0.276 and earlier. The vulnerability requires author-level privileges to exploit, meaning an attacker must either compromise a legitimate author account or trick an author into performing a malicious action. The attack vector is network-based and allows unauthenticated attackers to run arbitrary commands on the affected server. The vulnerability has been patched in version 1.0.277.
Affected products
- Rank Math SEO <= 1.0.276
Timeline
- 2026-08-27: disclosed: Published by Patchstack
- 2026-08-27: patched: Fixed in version 1.0.277