Unauthorized Data Modification in Rankology SEO and Analytics Tool for WordPress
CVE-2025-12958
2.7LOW
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 January 2026
What is CVE-2025-12958?
The Rankology SEO and Analytics Tool plugin for WordPress has a security issue that allows unauthorized modifications of data. This vulnerability arises from an inadequate capability check on the 'rankology_code_block' page, affecting all versions up to and including 2.0. Authenticated users with Editor-level access or higher can exploit this flaw to insert unwanted header and footer code blocks, potentially jeopardizing site integrity and security.
Affected Version(s)
Rankology SEO and Analytics Tool 0 <= 2.0