PT-2026-109505 · WordPress · Rank Math Seo
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rank Math SEO versions prior to 1.0.280
Description
The settings import feature fails to correctly validate the type of uploaded files. This allows users with administrator-level access to upload a PHP file, which can lead to remote code execution (RCE), a process where an attacker executes arbitrary code on the server.
Recommendations
Update Rank Math SEO to version 1.0.280 or later.
Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rank Math Seo