PT-2026-109505 · WordPress · Rank Math Seo

·

CVE-2026-104752

·

Published

2026-10-10

·

Updated

2026-10-10

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rank Math SEO versions prior to 1.0.280
Description The settings import feature fails to correctly validate the type of uploaded files. This allows users with administrator-level access to upload a PHP file, which can lead to remote code execution (RCE), a process where an attacker executes arbitrary code on the server.
Recommendations Update Rank Math SEO to version 1.0.280 or later.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104752

Affected Products

Rank Math Seo