Sceawere
Vulnerability Detail
CVE-2026-104754UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Rank Math Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.5
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Rank Math SEO
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Rank Math SEO WordPress plugin before 1.0.280 does not escape a stored redirection source value before outputting it in an administrative list view, allowing users who can manage redirections (Administrators by default) to store JavaScript that executes in the session of any user who later opens that view, including a Super Administrator on multisite.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.5",
"pubDate": "2026-10-10T06:16:39.603Z",
"pubdate": "2026-10-10T06:16:39.603Z",
"executiveSummary": "The Rank Math SEO WordPress plugin, in versions prior to 1.0.280, contains a stored Cross-Site Scripting (XSS) vulnerability within its redirection management functionality.\nThis flaw originates from the improper neutralization of input within the redirection source field, which is rendered without adequate output escaping in the administrative interface.\nAn attacker possessing the capability to manage redirections—typically an Administrator—can inject malicious JavaScript payloads. These scripts execute within the security context of any user who navigates to the affected administrative list view.\nThe impact is significant, as it permits the compromise of administrative sessions, including those of Super Administrators in multisite installations, potentially leading to full site takeover or arbitrary administrative actions.\nThe vulnerability is classified as stored XSS, reflecting a persistent threat vector where malicious payloads are saved to the database and executed server-side upon rendering. Mitigation requires updating the plugin to the version containing the security patch to ensure proper input sanitization and output escaping.",
"technicalDetails": "The vulnerability exists due to a lack of output encoding within the Rank Math redirection management module. Specifically, when a redirection rule is created or updated, the plugin fails to sanitize the 'source' path parameter before storing it in the database. Consequently, when the administrative user interface renders the list of redirection rules, the stored payload is echoed directly into the HTML document object model (DOM) without proper context-aware escaping.\nThe root cause is a failure to implement robust output sanitization practices using WordPress core functions such as esc_html() or esc_attr() in the relevant rendering logic for the redirection list view. This allows an attacker to inject arbitrary JavaScript tags (e.g., <script>alert(document.cookie)</script>) or attribute-based event handlers into the source field.\nThe attack flow follows a predictable pattern: first, an attacker with administrative privileges navigates to the redirection settings. Second, the attacker inputs a malicious script string into the 'Source URL' field. Because the plugin does not validate or escape this input, the malicious script is persisted in the WordPress options or custom post type table. Third, when a legitimate user, such as a Super Administrator, accesses the redirection list page, the malicious script is executed by the browser within the context of the user's active session.\nThe exploitation of this vulnerability is facilitated by the plugin's inherent privilege management. Since the administrative backend is the target, the payload benefits from the elevated permissions of the viewing user. In a multisite context, this allows for the escalation of privileges or cross-site impact if the payload interacts with network-wide administrative elements. Because the script executes in the victim's browser, the attacker can perform unauthorized actions on behalf of the victim, such as creating new rogue administrative accounts, modifying plugin settings, or exfiltrating sensitive session tokens (e.g., cookies).\nAffected versions include all iterations of Rank Math SEO prior to 1.0.280. The vulnerability is categorized as a stored XSS condition because the malicious payload remains resident on the server until explicitly removed by an authorized user or through database modification. The lack of output encoding is a critical oversight in the administrative display component, permitting persistent execution of unauthorized client-side code."
}