ZeroHour

CVE-2026-81757

mass

Authenticated PHP Deserialization RCE in Rank Math SEO WordPress Plugin

CVSS 3.1
7.2 high
EPSS
<1%p36
Published
()
Modified
AI analysis

CVE-2026-81757 is a deserialization-of-untrusted-data flaw (CWE-502) in the Rank Math SEO WordPress plugin that can lead to remote code execution. It is triggered when an authenticated user with at least author-level privileges submits crafted serialized input that the plugin processes, allowing attacker-controlled object instantiation and code execution. Successful exploitation grants arbitrary code execution on the web server, which typically enables full site compromise, data theft, or further lateral access. All WordPress sites running Rank Math SEO version 1.0.276 or earlier are affected. No public proof-of-concept exists, the flaw is not in the CISA KEV catalog, and EPSS assigns a 0.4% probability of exploitation within 30 days, so no exploitation is currently known.

What to do: Update Rank Math SEO to the latest available release (any version above 1.0.276) via the WordPress dashboard. Until updated, audit and limit accounts with author-level or higher privileges on affected sites and review logs for unexpected authenticated activity. Monitor plugin changelogs and the Patchstack advisory for the patched version.

Affected
Rank Math SEO (WordPress plugin)<= 1.0.276
Estimated exposure
mass≈2,000,000+ WordPress sites (plugin has roughly 2 million active installs) — Rank Math SEO is one of the most-installed WordPress SEO plugins with active installs reported in the millions on WordPress.org, though practical exposure is bounded by sites where author-level or higher accounts could be leveraged by an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.

Ecosystems
WordPress
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.