WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Seo By Rank Math?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Seo By Rank Math — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: seo-by-rank-math
  • 4000000+ instalaciones activas

google search consoleredirectionschemaseoxml sitemap

Estado de mantenimiento

  • Última versión conocida: 1.0.274.1
  • Requiere PHP: 7.4+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

20 CVEs conocidos registrados para Seo By Rank Math. Reportadas entre 2019 y 2026.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-34892 Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.271.1 Falta de control de autorización Media 6,5 < 1.0.271.1 1.0.271.1 2026-06-03 ✓ corregido en la última versión
CVE-2025-12714 Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.271.1 Falta de control de autorización Media 5,3 < 1.0.271.1 1.0.271.1 2026-05-28 ✓ corregido en la última versión
CVE-2025-64351 Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.253 Inserción de información sensible en los datos enviados Media 4,3 < 1.0.253 1.0.253 2025-09-11 ✓ corregido en la última versión
CVE-2025-64350 Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.253 Falta de control de autorización Baja 3,8 < 1.0.253 1.0.253 2025-09-11 ✓ corregido en la última versión
CVE-2024-13227 Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.236 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 1.0.236 1.0.236 2025-02-12 ✓ corregido en la última versión
CVE-2024-13229 Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.236 Control de acceso incorrecto Media 4,3 < 1.0.236 1.0.236 2025-02-12 ✓ corregido en la última versión
CVE-2024-11620 Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.232 Control incorrecto de la generación de código (inyección de código) Alta 7,2 < 1.0.232 1.0.232 2024-11-22 ✓ corregido en la última versión
CVE-2024-9161 Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.229 Falta de control de autorización Media 6,5 < 1.0.229 1.0.229 2024-10-04 ✓ corregido en la última versión

CVE-2026-34892

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.0.271. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-12714

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the update_site_editor_homepage function in all versions up to, and including, 1.0.271. This makes it possible for unauthenticated attackers to modify several plugin settings including homepage title, meta description, breadcrumbs label, and social media metadata, which can have severe impact on SEO rankings and display malicious content across all site pages where breadcrumbs are used.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-64351

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.252.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-64350

The Rank Math SEO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the track() function in versions up to, and including, 1.0.252.1. This makes it possible for authenticated attackers, with author-level access and above, to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-13227

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Rank Math API in all versions up to, and including, 1.0.235 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-13229

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the update_metadata() function in all versions up to, and including, 1.0.235. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete any schema metadata assigned to any post.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-11620

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.231. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-9161

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'update_metadata' function in all versions up to, and including, 1.0.228. This makes it possible for unauthenticated attackers to insert new and update existing metadata beginning with 'rank_math', and delete arbitrary existing user metadata and term metadata. Deleting existing usermeta can cause a loss of access to the administrator dashboard for any registered users, including Administrators.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

+ 20 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2024-9314 Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.229 Deserialización de datos no confiables Alta 7,2 < 1.0.229 1.0.229 2024-10-04 ✓ corregido en la última versión
CVE-2024-4627 Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.219 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 1.0.219 1.0.219 2024-06-11 ✓ corregido en la última versión
CVE-2024-4617 Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.219 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,4 < 1.0.219 1.0.219 2024-05-15 ✓ corregido en la última versión
CVE-2024-4335 Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.218 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 1.0.218 1.0.218 2024-05-03 ✓ corregido en la última versión
CVE-2024-3665 Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.217 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 1.0.217 1.0.217 2024-04-22 ✓ corregido en la última versión
CVE-2024-2536 Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.215 Validación incorrecta de la entrada Media 5,4 < 1.0.215 1.0.215 2024-03-21 ✓ corregido en la última versión
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.119.1 Desconocido < 1.0.119.1 1.0.119.1 2023-07-17 ✓ corregido en la última versión
CVE-2023-32600 Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.119.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 1.0.119.1 1.0.119.1 2023-07-17 ✓ corregido en la última versión
CVE-2023-23888 Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.119.1 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Alta 7,6 < 1.0.119.1 1.0.119.1 2023-02-10 ✓ corregido en la última versión
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.107.3 Desconocido < 1.0.107.3 1.0.107.3 2023-01-30 ✓ corregido en la última versión
CVE-2022-36376 Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.95.1 Falsificación de petición del lado del servidor (SSRF) Media 6,8 < 1.0.95.1 1.0.95.1 2022-08-12 ✓ corregido en la última versión
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.42.2 Desconocido < 1.0.42.2 1.0.42.2 2020-04-18 ✓ corregido en la última versión
CVE-2020-11514 Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.0.41 Falta de control de autorización Crítica 9,8 < 1.0.0.41 1.0.0.41 2020-03-25 ✓ corregido en la última versión
CVE-2020-11515 Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.0.41 Redirección de URL a un sitio no confiable (Open Redirect) Media 6,1 < 1.0.0.41 1.0.0.41 2020-03-25 ✓ corregido en la última versión
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27.1 Desconocido < 1.0.27.1 1.0.27.1 2019-06-25 ✓ corregido en la última versión
CVE-2019-14786 Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27.1 Falta de control de autorización Media 6,5 < 1.0.27.1 1.0.27.1 2019-06-21 ✓ corregido en la última versión
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27 Desconocido < 1.0.27 1.0.27 2019-06-18 ✓ corregido en la última versión
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27 Desconocido < 1.0.27 1.0.27 2019-06-18 ✓ corregido en la última versión
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.42.2 Desconocido < 1.0.42.2 1.0.42.2 ✓ corregido en la última versión
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27 Desconocido < 1.0.27 1.0.27 ✓ corregido en la última versión

CVE-2024-9314

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.228 via deserialization of untrusted input 'set_redirections' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-4627

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.218 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-4617

The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 1.0.218 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-4335

The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘textAlign’ parameter in versions up to, and including, 1.0.217 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-3665

The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's HowTo and FAQ widgets in all versions up to, and including, 1.0.216 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-2536

Update the WordPress Rank Math SEO plugin to the latest available version (at least 1.0.215). Ngô Thiên An (ancorn_) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Rank Math SEO Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.0.215. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.119.1

The Rank Math SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.0.119 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-32600

Update the WordPress Rank Math SEO plugin to the latest available version (at least 1.0.119.1). Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Rank Math SEO Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.0.119.1.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-23888

Update the Rank Math SEO plugin to the latest available version (at least 1.0.107.3). Rafie Muhammad (Patchstack) discovered and reported this Local File Inclusion vulnerability in WordPress Rank Math SEO Plugin. This could allow a malicious actor to include local files of the target website and show its output onto the screen. Files which store credentials, such as database credentials, could potentially allow complete database takeover. This vulnerability has been fixed in version 1.0.107.3.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.107.3

The RankMath SEO plugin for WordPress is vulnerable to Local File Inclusion via the 'update_schemas' and 'get_snippet_content' functions. This allows authenticated attackers, with contributor-level permissions and above, to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls or obtain sensitive data.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-36376

Update the WordPress WordPress SEO Plugin – Rank Math plugin to the latest available version (at least 1.0.95.1). Rafie Muhammad (Patchstack) discovered and reported this Server Side Request Forgery (SSRF) vulnerability in WordPress Rank Math SEO Plugin. This could allow a malicious actor to cause a website to execute website requests to an arbitrary domain of the attacker. This could allow a malicious actor to find sensitive information of other services running on the system. This vulnerability has been fixed in version 1.0.95.1.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.42.2

The Rank Math SEO plugin for WordPress is vulnerable to authorization bypass due to missing access controls on its "disable competitor plugins" functionality in versions up to, and including, 1.0.42.1. This makes it possible for subscriber-level attackers to disable other SEO or sitemap plugins on the site.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2020-11514

This plugin registered a REST-API endpoint, rankmath/v1/updateMeta, which failed to include a permission_callback used for capability checking. The endpoint called a function, update_metadata which could be used to update the slug on existing posts, or could be used to delete or update metadata for posts, comments, and terms. This endpoint also allowed for updating metadata for users. WordPress user permissions are stored in the usermeta table, which meant that an unauthenticated attacker could grant or revoke administrative privileges for any registered user.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

CVE-2020-11515

The WordPress SEO Plugin – Rank Math plugin includes a number of optional modules, including a module that can be used to create redirects on a site. In order to add this feature, the plugin registered a REST-API endpoint, rankmath/v1/updateRedirection, which failed to include a permission_callback for capability checking. The endpoint called a function, update_redirection, which could be used to create new redirects or modify existing redirects, with an important limitation. The redirect could not be set to an existing file or folder on the server, including the site’s main page. This limited the damage to some extent in that, while an attacker could create a redirect from most locations on the site, including new locations, or any existing post or page other than the homepage, they could not redirect visitors immediately upon accessing the site.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27.1

Authenticated Settings Reset vulnerability found in WordPress SEO By Rank Math plugin (versions <= 1.0.27).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2019-14786

The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb parameter.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27

Cross-Site Scripting (XSS) vulnerabilities found in WordPress SEO by Rank Math (versions <= 1.0.26).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27

The Rank Math SEO is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including 1.0.26.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.42.2

Missing access controls on the GET requests to deactivate competitors' plugins. This could allow any authenticated users (such as subscribers) to deactivate the SEO and Sitemap plugins from competitors. The attack could also be performed via CSRF.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27

The changelog file states "Added some important security fixes", and various variables can be found being HTML escaped in the code changes.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén Seo By Rank Math actualizado — 1.0.274.1 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.