SecAlerts
rankmath logo

rankmath

Security Risk Profile

35
/100
low

Security Risk Score

Comprehensive risk assessment based on 15 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from August 15, 2019 to present

15
Total CVEs
5
Critical+High
0
Exploited
1
Unpatched

Threat Assessment

Avg CVSS
6.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
35/100
low

Severity Distribution

Critical
2
High
3
Medium
10
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
XSS
7
2
Path Traversal
1
3
Input Validation
1
4
SSRF
1

Most Affected Products

1. rankmath Seo Wordpress14
2. Rank Math SEO – AI SEO Tools to Dominate SEO Rankings2
3. Rank Math Rank Math SEO2
4. MyThemeShop Rank Math SEO1
5. WordPress Rank Math SEO1

Recent Vulnerabilities

See more →
CVE-2024-13229
CVSS 4.3medium

Rank Math SEO <= 1.0.235 - Missing Authorization to Authenticated (Contributor+) Arbitrary Schema Deletion

2/13/2025
CVE-2024-13227
CVSS 6.4medium

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.235 - Authenticated (Contributor+) Stored Cross-Site Scripting via Rank Math API

2/13/2025
CVE-2024-9314
CVSS 7.2EPSS 0%high

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Authenticated (Administrator+) PHP Object Injection

10/5/2024
CVE-2024-9161
CVSS 6.5EPSS 0%medium

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Missing Authorization to Unauthenticated User and Term Metadata Insert, Update, and Delete

10/5/2024
CVE-2024-4627
CVSS 5.5medium

Rank Math SEO < 1.0.219 - Authenticated Stored XSS

7/2/2024🔧 No Patch
CVE-2023-23888
CVSS 8.8high

WordPress Rank Math SEO plugin <= 1.0.107.2 - Local File Inclusion vulnerability

5/17/2024
CVE-2024-4335
CVSS 6.4EPSS 0%medium

Rank Math SEO with AI Best SEO Tools <= 1.0.217 - Authenticated (Contributor+) Stored Cross-Site Scripting

5/9/2024🔧 No Patch
CVE-2024-3665
CVSS 6.4EPSS 0%medium

Rank Math SEO with AI SEO Tools <= 1.0.216 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleWrapper'

4/23/2024
CVE-2024-2536
CVSS 6.4medium

Rank Math SEO with AI SEO Tools <= 1.0.214 - Authenticated(Contributor+) Stored Cross-Site Scripting via HowTo block attributes

4/9/2024
CVE-2023-32600
CVSS 6.5medium

WordPress Rank Math SEO Plugin <= 1.0.119 is vulnerable to Cross Site Scripting (XSS)

8/5/2023

Monitor rankmath in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.