20 CVEs conocidos registrados para Seo By Rank Math.
Reportadas entre 2019 y 2026.
+ 20 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2024-9314
|
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.229 |
Deserialización de datos no confiables |
Alta
7,2
|
< 1.0.229
|
1.0.229 |
2024-10-04 |
✓ corregido en la última versión
|
|
CVE-2024-4627
|
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.219 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 1.0.219
|
1.0.219 |
2024-06-11 |
✓ corregido en la última versión
|
|
CVE-2024-4617
|
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.219 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,4
|
< 1.0.219
|
1.0.219 |
2024-05-15 |
✓ corregido en la última versión
|
|
CVE-2024-4335
|
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.218 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 1.0.218
|
1.0.218 |
2024-05-03 |
✓ corregido en la última versión
|
|
CVE-2024-3665
|
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.217 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 1.0.217
|
1.0.217 |
2024-04-22 |
✓ corregido en la última versión
|
|
CVE-2024-2536
|
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.215 |
Validación incorrecta de la entrada |
Media
5,4
|
< 1.0.215
|
1.0.215 |
2024-03-21 |
✓ corregido en la última versión
|
|
—
|
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.119.1 |
— |
Desconocido
|
< 1.0.119.1
|
1.0.119.1 |
2023-07-17 |
✓ corregido en la última versión
|
|
CVE-2023-32600
|
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.119.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 1.0.119.1
|
1.0.119.1 |
2023-07-17 |
✓ corregido en la última versión
|
|
CVE-2023-23888
|
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.119.1 |
Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) |
Alta
7,6
|
< 1.0.119.1
|
1.0.119.1 |
2023-02-10 |
✓ corregido en la última versión
|
|
—
|
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.107.3 |
— |
Desconocido
|
< 1.0.107.3
|
1.0.107.3 |
2023-01-30 |
✓ corregido en la última versión
|
|
CVE-2022-36376
|
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.95.1 |
Falsificación de petición del lado del servidor (SSRF) |
Media
6,8
|
< 1.0.95.1
|
1.0.95.1 |
2022-08-12 |
✓ corregido en la última versión
|
|
—
|
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.42.2 |
— |
Desconocido
|
< 1.0.42.2
|
1.0.42.2 |
2020-04-18 |
✓ corregido en la última versión
|
|
CVE-2020-11514
|
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.0.41 |
Falta de control de autorización |
Crítica
9,8
|
< 1.0.0.41
|
1.0.0.41 |
2020-03-25 |
✓ corregido en la última versión
|
|
CVE-2020-11515
|
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.0.41 |
Redirección de URL a un sitio no confiable (Open Redirect) |
Media
6,1
|
< 1.0.0.41
|
1.0.0.41 |
2020-03-25 |
✓ corregido en la última versión
|
|
—
|
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27.1 |
— |
Desconocido
|
< 1.0.27.1
|
1.0.27.1 |
2019-06-25 |
✓ corregido en la última versión
|
|
CVE-2019-14786
|
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27.1 |
Falta de control de autorización |
Media
6,5
|
< 1.0.27.1
|
1.0.27.1 |
2019-06-21 |
✓ corregido en la última versión
|
|
—
|
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27 |
— |
Desconocido
|
< 1.0.27
|
1.0.27 |
2019-06-18 |
✓ corregido en la última versión
|
|
—
|
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27 |
— |
Desconocido
|
< 1.0.27
|
1.0.27 |
2019-06-18 |
✓ corregido en la última versión
|
|
—
|
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.42.2 |
— |
Desconocido
|
< 1.0.42.2
|
1.0.42.2 |
— |
✓ corregido en la última versión
|
|
—
|
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27 |
— |
Desconocido
|
< 1.0.27
|
1.0.27 |
— |
✓ corregido en la última versión
|
CVE-2024-9314
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.228 via deserialization of untrusted input 'set_redirections' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-4627
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.218 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-4617
The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 1.0.218 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-4335
The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘textAlign’ parameter in versions up to, and including, 1.0.217 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-3665
The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's HowTo and FAQ widgets in all versions up to, and including, 1.0.216 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-2536
Update the WordPress Rank Math SEO plugin to the latest available version (at least 1.0.215).
Ngô Thiên An (ancorn_) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Rank Math SEO Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.0.215.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.119.1
The Rank Math SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.0.119 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-32600
Update the WordPress Rank Math SEO plugin to the latest available version (at least 1.0.119.1).
Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Rank Math SEO Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.0.119.1.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-23888
Update the Rank Math SEO plugin to the latest available version (at least 1.0.107.3).
Rafie Muhammad (Patchstack) discovered and reported this Local File Inclusion vulnerability in WordPress Rank Math SEO Plugin. This could allow a malicious actor to include local files of the target website and show its output onto the screen. Files which store credentials, such as database credentials, could potentially allow complete database takeover. This vulnerability has been fixed in version 1.0.107.3.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.107.3
The RankMath SEO plugin for WordPress is vulnerable to Local File Inclusion via the 'update_schemas' and 'get_snippet_content' functions. This allows authenticated attackers, with contributor-level permissions and above, to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls or obtain sensitive data.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-36376
Update the WordPress WordPress SEO Plugin – Rank Math plugin to the latest available version (at least 1.0.95.1).
Rafie Muhammad (Patchstack) discovered and reported this Server Side Request Forgery (SSRF) vulnerability in WordPress Rank Math SEO Plugin. This could allow a malicious actor to cause a website to execute website requests to an arbitrary domain of the attacker. This could allow a malicious actor to find sensitive information of other services running on the system. This vulnerability has been fixed in version 1.0.95.1.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.42.2
The Rank Math SEO plugin for WordPress is vulnerable to authorization bypass due to missing access controls on its "disable competitor plugins" functionality in versions up to, and including, 1.0.42.1. This makes it possible for subscriber-level attackers to disable other SEO or sitemap plugins on the site.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2020-11514
This plugin registered a REST-API endpoint, rankmath/v1/updateMeta, which failed to include a permission_callback used for capability checking. The endpoint called a function, update_metadata which could be used to update the slug on existing posts, or could be used to delete or update metadata for posts, comments, and terms. This endpoint also allowed for updating metadata for users. WordPress user permissions are stored in the usermeta table, which meant that an unauthenticated attacker could grant or revoke administrative privileges for any registered user.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
CVE-2020-11515
The WordPress SEO Plugin – Rank Math plugin includes a number of optional modules, including a module that can be used to create redirects on a site. In order to add this feature, the plugin registered a REST-API endpoint, rankmath/v1/updateRedirection, which failed to include a permission_callback for capability checking. The endpoint called a function, update_redirection, which could be used to create new redirects or modify existing redirects, with an important limitation. The redirect could not be set to an existing file or folder on the server, including the site’s main page. This limited the damage to some extent in that, while an attacker could create a redirect from most locations on the site, including new locations, or any existing post or page other than the homepage, they could not redirect visitors immediately upon accessing the site.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27.1
Authenticated Settings Reset vulnerability found in WordPress SEO By Rank Math plugin (versions <= 1.0.27).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2019-14786
The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb parameter.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27
Cross-Site Scripting (XSS) vulnerabilities found in WordPress SEO by Rank Math (versions <= 1.0.26).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27
The Rank Math SEO is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including 1.0.26.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.42.2
Missing access controls on the GET requests to deactivate competitors' plugins. This could allow any authenticated users (such as subscribers) to deactivate the SEO and Sitemap plugins from competitors. The attack could also be performed via CSRF.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.27
The changelog file states "Added some important security fixes", and various variables can be found being HTML escaped in the code changes.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Mantén Seo By Rank Math actualizado — 1.0.274.1 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.