WordPress Plugin Vulnerabilities

Rank Math SEO < 1.0.280 - Admin+ Arbitrary File Upload to RCE via Settings Import

Description

The plugin does not correctly validate the type of a file uploaded through its settings import feature, allowing users with administrator-level access to upload a PHP file and achieve remote code execution.

Proof of Concept

Affects Plugins

Fixed in 1.0.280

References

Miscellaneous

Original Researcher
Karthik Ramakrishnan
Submitter
Karthik Ramakrishnan
Verified
Yes

Timeline

Publicly Published
2026-10-08 (about 2 days ago)
Added
2026-10-08 (about 1 day ago)
Last Updated
2026-10-08 (about 1 day ago)

Other