CVE-2026-104754
Received
Received - Intake
Stored XSS in Rank Math SEO WordPress Plugin
Vulnerability report for CVE-2026-104754, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-10
Last updated on: 2026-10-10
Assigner: WPScan
Description
Description
The Rank Math SEO WordPress plugin before 1.0.280 does not escape a stored redirection source value before outputting it in an administrative list view, allowing users who can manage redirections (Administrators by default) to store JavaScript that executes in the session of any user who later opens that view, including a Super Administrator on multisite.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Unknown | Rank | Math SEO 0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |