CVE-2026-104753: Rank Math SEO < 1.0.280 - Admin+ SQLi via 'per_page' Parameter
The Rank Math SEO WordPress plugin before 1.0.280 does not properly sanitise and escape a parameter before using it in a SQL query, allowing high-privilege users such as administrators to perform SQL injection attacks.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs high-privilege access to the WordPress site, such as an administrator account. The available information does not indicate that unauthenticated or low-privilege users can exploit it.
Which installations are affected?
Rank Math SEO versions earlier than 1.0.280 are affected. The issue involves the per_page parameter being used in a SQL query without proper sanitization and escaping.
What should teams do if they cannot update immediately?
Restrict and closely review administrator access, since exploitation requires high-privilege access. Monitor for unexpected administrator activity and protect admin credentials while an update is pending.