Sceawere

Vulnerability Detail

CVE-2026-104752UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Rank Math Arbitrary File Upload

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
8h ago
Vendor
Unknown
Product
Rank Math SEO
Attack Type
CWE-434 Unrestricted Upload of File with Dangerous Type
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Rank Math SEO WordPress plugin before 1.0.280 does not correctly validate the type of a file uploaded through its settings import feature, allowing users with administrator-level access to upload a PHP file and achieve remote code execution.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-10T06:16:39.383Z",
  "pubdate": "2026-10-10T06:16:39.383Z",
  "executiveSummary": "The Rank Math SEO plugin for WordPress, in versions prior to 1.0.280, contains an arbitrary file upload vulnerability within its settings import functionality.\nThis vulnerability is classified as an Unrestricted Upload of File with Dangerous Type, which can lead to Remote Code Execution (RCE).\nThe flaw stems from insufficient input validation regarding the file type permitted during the configuration import process.\nAn attacker possessing administrator-level privileges can leverage this oversight to upload malicious PHP scripts to the web server.\nUpon successful execution of the uploaded payload, an attacker can achieve full system compromise, executing arbitrary code within the context of the web server process.\nDue to the high impact of RCE, the risk is classified as critical, necessitating an immediate update to the patched version of the software.",
  "technicalDetails": "The vulnerability resides in the settings import mechanism of the Rank Math SEO plugin, which fails to enforce strict mime-type or file extension validation for uploaded configuration files.\nThe root cause is a deficiency in the server-side validation logic, which assumes that imported files will strictly adhere to the expected format, typically JSON or equivalent serialized data structures.\nAn authenticated user with administrative privileges can bypass intended file constraints by providing a file containing malicious PHP code disguised as a legitimate configuration file.\nThe attack flow proceeds as follows: First, the attacker navigates to the administrative interface responsible for importing SEO settings. Second, the attacker uploads a crafted PHP script designed to execute system commands or provide a web shell. Third, the plugin, lacking adequate validation, saves the file to a directory accessible by the web server. Finally, the attacker triggers the execution of the uploaded script by requesting the file path directly via the browser.\nBecause the server interprets the uploaded file as a valid script, the embedded payload executes with the privileges of the web server user. This permits the attacker to interact with the underlying operating system, read/modify sensitive database content, traverse the filesystem, or install backdoors for persistent access.\nThe vulnerability affects Rank Math SEO versions before 1.0.280. Successful exploitation requires the attacker to have already achieved authenticated access as a WordPress administrator. While this limits the initial attack vector, it represents a significant privilege escalation and persistence mechanism, as compromised administrative accounts can be used to permanently subvert the security posture of the entire WordPress installation.\nThe impact of this vulnerability is severe, as it facilitates full Remote Code Execution. An attacker can manipulate the WordPress environment, exfiltrate data, or pivot to internal network resources, effectively neutralizing the integrity and availability of the host infrastructure."
}
CVE-2026-104752: Rank Math Arbitrary File Upload (HIGH Severity, CVSS: 7.2) | Sceawere