Cross Site Scripting Vulnerability in Rank Math SEO Plugin
CVE-2026-66702
7.1HIGH
What is CVE-2026-66702?
An unauthenticated Cross Site Scripting (XSS) vulnerability has been identified in the Rank Math SEO plugin for WordPress, affecting versions up to 1.0.274.1. This security flaw allows attackers to inject arbitrary scripts into web pages viewed by users, potentially leading to data theft and unauthorized actions performed on behalf of users. Website administrators are advised to update their plugins to mitigate the risks associated with this vulnerability.
Affected Version(s)
Rank Math SEO <= 1.0.274.1