PT-2026-44796 · WordPress · Rank Math Seo

·

CVE-2025-12714

·

Published

2026-05-29

·

Updated

2026-07-21

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Rank Math SEO versions prior to 1.0.272
Description The Rank Math SEO plugin for WordPress allows unauthorized access because the update site editor homepage() function lacks a capability check. This allows unauthenticated attackers to modify various plugin settings, such as the homepage title, meta description, breadcrumbs label, and social media metadata. Such modifications can negatively impact SEO rankings and enable the display of malicious content on all site pages where breadcrumbs are implemented.
Recommendations Update the plugin to version 1.0.272 or later. As a temporary workaround, restrict access to the update site editor homepage() function until the update is applied.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-12714

Affected Products

Rank Math Seo