CVE-2026-104754
Rank Math SEO < 1.0.280 - Admin+ Stored XSS via Redirection Source URL
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Rank Math SEO WordPress plugin before 1.0.280 does not escape a stored redirection source value before outputting it in an administrative list view, allowing users who can manage redirections (Administrators by default) to store JavaScript that executes in the session of any user who later opens that view, including a Super Administrator on multisite.
| Vendor | unknown |
| Product | rank math seo |
| Published | Oct 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown rank math seo
Be the first to know when new unknown vulnerabilities affecting unknown rank math seo are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Rank Math SEO
0 < 1.0.280
References
Credits
Karthik Ramakrishnan WPScan