CVE-2025-64351: WordPress Rank Math SEO plugin <= 1.0.252.1 - Sensitive Data Exposure vulnerability
Published Oct 31, 2025
·Updated
Insertion of Sensitive Information Into Sent Data vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Retrieve Embedded Sensitive Data.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1.
Affected Software
2 affected components
Rank Math SEO<=1.0.252.1
WordPress Rank Math SEO plugin<=1.0.252.1
Event History
Oct 31, 2025
CVE Published
via MITRE·11:42 AM
Data Sourced
via MITRE·11:42 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-64351?
CVE-2025-64351 is classified as a vulnerability that allows the retrieval of embedded sensitive data, which poses a significant security risk.
2
How do I fix CVE-2025-64351?
To mitigate CVE-2025-64351, update the Rank Math SEO plugin to a version higher than 1.0.252.1.
3
What versions of Rank Math SEO are affected by CVE-2025-64351?
CVE-2025-64351 affects Rank Math SEO versions up to and including 1.0.252.1.
4
What type of vulnerability is CVE-2025-64351?
CVE-2025-64351 is categorized as an Insertion of Sensitive Information Into Sent Data vulnerability.
5
Can CVE-2025-64351 affect WordPress websites?
Yes, CVE-2025-64351 affects WordPress websites that use the Rank Math SEO plugin versions up to 1.0.252.1.