Rankmath's vulnerability profile centers on a narrowly scoped WordPress SEO plugin product that, despite modest volume, holds a prominent position in the WordPress ecosystem due to its wide adoption across content-heavy websites. Vulnerabilities affecting the vendor skew toward serious outcomes with an elevated share reaching critical severity and a strong tendency toward public exploit availability, reflecting the plugin's web-facing role and exposure to input from both administrators and untrusted external sources. The recurring weakness classes—including cross-site scripting, missing authorization, untrusted deserialization, and improper access control—are characteristic of web applications that handle user input and manage permission boundaries, and have historically attracted public tooling due to the accessibility of WordPress environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rankmath over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11514CRITICAL The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke admi | Apr 7, 2020 | 9.8 | 44 | NO | YES |
CVE-2022-36376CRITICAL Server-Side Request Forgery (SSRF) vulnerability in Rank Math SEO plugin <= 1.0.95 at WordPress. | Sep 9, 2022 | 9.8 | 31 | NO | NO |
CVE-2024-9161MEDIUM The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the | Oct 5, 2024 | 6.5 | 30 | NO | YES |
CVE-2020-11515MEDIUM The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1 | Apr 7, 2020 | 6.1 | 30 | NO | YES |
CVE-2023-23888HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rank Math Rank Math SEO allows Path Traversal.This issue affects Rank Math SEO: from | May 17, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-9314HIGH The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.228 via deserializati | Oct 5, 2024 | 7.2 | 22 | NO | NO |
CVE-2019-14786MEDIUM The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb parameter. | Aug 15, 2019 | 6.5 | 22 | NO | NO |
CVE-2023-32800MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in One Rank Math SEO PRO plugin <= 3.0.35 versions. | May 28, 2023 | 6.1 | 20 | NO | NO |
CVE-2024-4627MEDIUM The Rank Math SEO WordPress plugin before 1.0.219 does not sanitise and escape some of its settings, which could allow users with access to the General Settings (by default admin, | Jul 2, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-2536MEDIUM The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HowTo block attributes in all versions up to, and including, 1.0.214 d | Apr 9, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rankmath.
Media articles that mention a CVE ID that affects a product developed by Rankmath — matched by CVE ID, not by vendor name.