WordPress Plugin Vulnerabilities
Rank Math SEO < 1.0.280 - Admin+ Arbitrary File Upload to RCE via Settings Import
Description
The plugin does not correctly validate the type of a file uploaded through its settings import feature, allowing users with administrator-level access to upload a PHP file and achieve remote code execution.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Karthik Ramakrishnan
Submitter
Karthik Ramakrishnan
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-10-08 (about 2 days ago)
Added
2026-10-08 (about 1 day ago)
Last Updated
2026-10-08 (about 1 day ago)