Sceawere

Vulnerability Detail

CVE-2026-104753UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Rank Math SEO SQL Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.1
Creation Date
8h ago
Vendor
Unknown
Product
Rank Math SEO
Attack Type
CWE-89 SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Rank Math SEO WordPress plugin before 1.0.280 does not properly sanitise and escape a parameter before using it in a SQL query, allowing high-privilege users such as administrators to perform SQL injection attacks.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.1",
  "pubDate": "2026-10-10T06:16:39.500Z",
  "pubdate": "2026-10-10T06:16:39.500Z",
  "executiveSummary": "The Rank Math SEO plugin for WordPress, in versions prior to 1.0.280, is susceptible to an authenticated SQL injection vulnerability.\nThis vulnerability stems from inadequate sanitization and improper escaping of user-supplied input before that data is processed within SQL queries.\nThe vulnerability allows high-privilege users, specifically administrators, to execute arbitrary SQL commands against the underlying WordPress database.\nThe potential impact includes unauthorized data exfiltration, database modification, and administrative bypass, leading to full compromise of the WordPress environment.\nSuccessful exploitation requires high-privileged authentication, limiting the attack surface to malicious insiders or attackers who have already compromised an administrative account.\nThe risk is significant due to the nature of SQL injection, which can lead to complete database manipulation and potential remote code execution depending on the database configuration.",
  "technicalDetails": "The root cause of this vulnerability is the failure of the Rank Math SEO plugin to sanitize and escape input parameters before they are concatenated into a SQL statement.\nIn versions prior to 1.0.280, the plugin processes specific user-supplied parameters through database queries without utilizing proper WordPress database API methods, such as $wpdb->prepare(), which are designed to safely handle dynamic SQL construction.\nThe vulnerability exists in the plugin's interaction with the database, where user input is directly inserted into a SQL query string.\nAn authenticated user with administrative privileges can supply malicious SQL fragments through the vulnerable parameter.\nBecause the input is not sanitized, the database engine interprets the malicious input as part of the intended SQL command, allowing the attacker to alter the query logic.\nThe attack flow proceeds as follows: 1) The attacker logs into the WordPress dashboard as an administrator. 2) The attacker navigates to the specific administrative feature within the Rank Math SEO plugin that accepts the vulnerable input. 3) The attacker intercepts or submits a crafted request containing SQL injection payloads within the parameter. 4) The plugin backend accepts this input and embeds it directly into a SQL query executed against the WordPress database. 5) The database executes the injected commands, which may include UNION SELECT statements, boolean-based blind injection, or error-based injection techniques.\nThis allows the attacker to extract sensitive information such as password hashes, user metadata, or configuration details, or potentially perform unauthorized data deletion or modification.\nThe impact of a successful attack is critical, as it bypasses the application's intended logic and provides the attacker with direct, unrestricted control over the database, which is the repository for the entire site's content and user data."
}
CVE-2026-104753: Rank Math SEO SQL Injection (MEDIUM Severity, CVSS: 4.1) | Sceawere