CVE-2026-81757
massAuthenticated PHP Deserialization RCE in Rank Math SEO WordPress Plugin
CVE-2026-81757 is a deserialization-of-untrusted-data flaw (CWE-502) in the Rank Math SEO WordPress plugin that can lead to remote code execution. It is triggered when an authenticated user with at least author-level privileges submits crafted serialized input that the plugin processes, allowing attacker-controlled object instantiation and code execution. Successful exploitation grants arbitrary code execution on the web server, which typically enables full site compromise, data theft, or further lateral access. All WordPress sites running Rank Math SEO version 1.0.276 or earlier are affected. No public proof-of-concept exists, the flaw is not in the CISA KEV catalog, and EPSS assigns a 0.4% probability of exploitation within 30 days, so no exploitation is currently known.
What to do: Update Rank Math SEO to the latest available release (any version above 1.0.276) via the WordPress dashboard. Until updated, audit and limit accounts with author-level or higher privileges on affected sites and review logs for unexpected authenticated activity. Monitor plugin changelogs and the Patchstack advisory for the patched version.
| Rank Math SEO (WordPress plugin) | <= 1.0.276 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.