Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rankmath

First CVE: Aug 15, 2019Active for: 7 yearsTotal CVEs: 15
32.9
VTI Score
Medium

Rankmath's vulnerability profile centers on a narrowly scoped WordPress SEO plugin product that, despite modest volume, holds a prominent position in the WordPress ecosystem due to its wide adoption across content-heavy websites. Vulnerabilities affecting the vendor skew toward serious outcomes with an elevated share reaching critical severity and a strong tendency toward public exploit availability, reflecting the plugin's web-facing role and exposure to input from both administrators and untrusted external sources. The recurring weakness classes—including cross-site scripting, missing authorization, untrusted deserialization, and improper access control—are characteristic of web applications that handle user input and manage permission boundaries, and have historically attracted public tooling due to the accessibility of WordPress environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 40% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Rankmath over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 15, 2019
6 years ago
Most Recent CVE
Feb 13, 2025
526 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-11514CRITICAL
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke admi
Apr 7, 20209.844NOYES
CVE-2022-36376CRITICAL
Server-Side Request Forgery (SSRF) vulnerability in Rank Math SEO plugin <= 1.0.95 at WordPress.
Sep 9, 20229.831NONO
CVE-2024-9161MEDIUM
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the
Oct 5, 20246.530NOYES
CVE-2020-11515MEDIUM
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1
Apr 7, 20206.130NOYES
CVE-2023-23888HIGH
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rank Math Rank Math SEO allows Path Traversal.This issue affects Rank Math SEO: from
May 17, 20248.824NONO
CVE-2024-9314HIGH
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.228 via deserializati
Oct 5, 20247.222NONO
CVE-2019-14786MEDIUM
The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb parameter.
Aug 15, 20196.522NONO
CVE-2023-32800MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in One Rank Math SEO PRO plugin <= 3.0.35 versions.
May 28, 20236.120NONO
CVE-2024-4627MEDIUM
The Rank Math SEO WordPress plugin before 1.0.219 does not sanitise and escape some of its settings, which could allow users with access to the General Settings (by default admin,
Jul 2, 20245.418NONO
CVE-2024-2536MEDIUM
The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HowTo block attributes in all versions up to, and including, 1.0.214 d
Apr 9, 20245.418NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
73%
13%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (46.7%)
Unknown0 (0.0%)
Required8 (53.3%)
Privileges Required
Low9 (60.0%)
High1 (6.7%)
None5 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
20.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rankmath.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rankmath — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rankmath's Products

View all 4 CNAs →

Top CWEs