CVE-2026-104754: Rank Math SEO < 1.0.280 - Admin+ Stored XSS via Redirection Source URL
The Rank Math SEO WordPress plugin before 1.0.280 does not escape a stored redirection source value before outputting it in an administrative list view, allowing users who can manage redirections (Administrators by default) to store JavaScript that executes in the session of any user who later opens that view, including a Super Administrator on multisite.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue under the default WordPress permissions model?
A user who can manage Rank Math redirections can store the malicious source value. By default, this capability is available to Administrators; on multisite, a stored payload can execute when a Super Administrator opens the affected administrative list view.
What user interaction is required for the stored payload to execute?
An attacker must first save JavaScript in a redirection source value. The JavaScript executes only when another user later opens the administrative list view that displays that stored value.
Which versions are affected?
Rank Math SEO versions before 1.0.280 are affected. Updating to version 1.0.280 or later addresses the described unescaped output.