CVE-2026-104754
Received Received - Intake

Stored XSS in Rank Math SEO WordPress Plugin

Vulnerability report for CVE-2026-104754, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: WPScan

Description

The Rank Math SEO WordPress plugin before 1.0.280 does not escape a stored redirection source value before outputting it in an administrative list view, allowing users who can manage redirections (Administrators by default) to store JavaScript that executes in the session of any user who later opens that view, including a Super Administrator on multisite.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Rank Math SEO 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored cross-site scripting (XSS) issue in the Rank Math SEO WordPress plugin before version 1.0.280. It occurs because the plugin does not properly escape a stored redirection source value before displaying it in an administrative list view. This allows administrators to inject malicious JavaScript code that executes when other users, including Super Administrators on multisite installations, view the affected page.

Detection Guidance

Check for unauthorized JavaScript in redirection source values in the Rank Math SEO plugin's administrative list view. Manually review stored redirections for suspicious entries.

Impact Analysis

If you manage a WordPress site using Rank Math SEO before version 1.0.280, an attacker with administrator privileges could inject malicious scripts. These scripts could steal session cookies, perform actions on your behalf, or redirect you to phishing sites when you access the plugin's redirection management interface.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, which may violate GDPR's data protection requirements or HIPAA's security rules for protected health information. If exploited, it could result in data breaches, unauthorized data access, or loss of data integrity, potentially leading to regulatory penalties.

Mitigation Strategies

Update the Rank Math SEO plugin to version 1.0.280 or later immediately. If updating is not possible, disable the plugin until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104754. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart