CVE-2026-81757: WordPress Rank Math SEO plugin <= 1.0.276 - Remote Code Execution (RCE) vulnerability
Published Aug 28, 2026
·Updated
Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
Affected Software
1 affected component
WordPress Rank Math SEO plugin<=1.0.276
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Rank Math SEO pluginto a version that resolves this vulnerability.Fixed in 1.0.277
Event History
Aug 28, 2026
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability requires Author-level privileges. It is not described as exploitable by an unauthenticated or lower-privileged user.
2
Which installations are affected?
Rank Math SEO plugin versions 1.0.276 and earlier are affected.