VendorsRankMathseoany version
Vulnerabilities

RankMath SEO any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2020-11514
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.
Published 2020-04-07 · Modified
9.8EPSS 0.091
CVE-2022-36376
WordPress Rank Math SEO plugin <= 1.0.95 - Server-Side Request Forgery (SSRF) vulnerability
Published 2022-09-09 · Modified
9.8EPSS 0.010
CVE-2023-23888
WordPress Rank Math SEO plugin <= 1.0.107.2 - Local File Inclusion vulnerability
Published 2024-05-17 · Analyzed
8.8EPSS 0.009
CVE-2024-9314
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Authenticated (Administrator+) PHP Object Injection
Published 2024-10-05 · Analyzed
7.2EPSS 0.008
CVE-2024-9161
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Missing Authorization to Unauthenticated User and Term Metadata Insert, Update, and Delete
Published 2024-10-05 · Analyzed
6.5EPSS 0.021
CVE-2019-14786
The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb parameter.
Published 2019-08-15 · Modified
6.5EPSS 0.014
CVE-2023-32600
WordPress Rank Math SEO Plugin <= 1.0.119 is vulnerable to Cross Site Scripting (XSS)
Published 2023-08-05 · Modified
6.5EPSS 0.004
CVE-2024-13227
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.235 - Authenticated (Contributor+) Stored Cross-Site Scripting via Rank Math API
Published 2025-02-13 · Analyzed
6.4EPSS 0.005
CVE-2024-3665
Rank Math SEO with AI SEO Tools <= 1.0.216 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleWrapper'
Published 2024-04-23 · Modified
6.4EPSS 0.005
CVE-2024-4335
Rank Math SEO with AI Best SEO Tools <= 1.0.217 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-05-09 · Modified
6.4EPSS 0.004
CVE-2024-2536
Rank Math SEO with AI SEO Tools <= 1.0.214 - Authenticated(Contributor+) Stored Cross-Site Scripting via HowTo block attributes
Published 2024-04-09 · Modified
6.4EPSS 0.003
CVE-2020-11515
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint. In other words, this is not an "Open Redirect" issue; instead, it allows the attacker to create a new URI with an arbitrary name (e.g., the /exampleredirect URI).
Published 2020-04-07 · Modified
6.1EPSS 0.021
CVE-2024-4627
Rank Math SEO < 1.0.219 - Authenticated Stored XSS
Published 2024-07-02 · Modified
5.5EPSS 0.004
CVE-2024-13229
Rank Math SEO <= 1.0.235 - Missing Authorization to Authenticated (Contributor+) Arbitrary Schema Deletion
Published 2025-02-13 · Analyzed
4.3EPSS 0.005