Broken Access Control in Rank Math SEO Plugin by Rank Math
CVE-2026-34892

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 June 2026

What is CVE-2026-34892?

A broken access control vulnerability in the Rank Math SEO plugin could potentially allow unauthorized users to access sensitive features and data, impacting the security of WordPress sites utilizing this plugin, specifically in versions 1.0.271 and earlier.

Affected Version(s)

Rank Math SEO <= 1.0.271

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Herman | Patchstack Bug Bounty Program
.