Description
The Rank Math SEO WordPress plugin before 1.0.280 does not escape a stored redirection source value before outputting it in an administrative list view, allowing users who can manage redirections (Administrators by default) to store JavaScript that executes in the session of any user who later opens that view, including a Super Administrator on multisite.
Published: 2026-10-10
Score: 3.5 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 10 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sat, 10 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Rank Math SEO WordPress plugin before 1.0.280 does not escape a stored redirection source value before outputting it in an administrative list view, allowing users who can manage redirections (Administrators by default) to store JavaScript that executes in the session of any user who later opens that view, including a Super Administrator on multisite.
Title Rank Math SEO < 1.0.280 - Admin+ Stored XSS via Redirection Source URL
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-10T12:06:42.507Z

Reserved: 2026-10-02T12:14:30.934Z

Link: CVE-2026-104754

cve-icon Vulnrichment

Updated: 2026-10-10T12:04:17.766Z

cve-icon NVD

Status : Received

Published: 2026-10-10T06:16:39.603

Modified: 2026-10-10T12:16:45.263

Link: CVE-2026-104754

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T07:30:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')