WordPress Plugin Vulnerabilities

Rank Math SEO < 1.0.280 - Admin+ Stored XSS via Redirection Source URL

Description

The plugin does not escape a stored redirection source value before outputting it in an administrative list view, allowing users who can manage redirections (Administrators by default) to store JavaScript that executes in the session of any user who later opens that view, including a Super Administrator on multisite.

Proof of Concept

Affects Plugins

Fixed in 1.0.280

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Karthik Ramakrishnan
Submitter
Karthik Ramakrishnan
Verified
Yes

Timeline

Publicly Published
2026-10-08 (about 2 days ago)
Added
2026-10-08 (about 1 day ago)
Last Updated
2026-10-08 (about 1 day ago)

Other