CVE-2026-104754

LOWCVSS 3.5/10

Last modified

CVE-2026-104754 is a low-severity vulnerability rated 3.5/10 on the CVSS scale. The Rank Math SEO WordPress plugin before 1.0.280 does not escape a stored redirection source value before outputting it in an administrative list view, allowing users who can manage redirections (Administrators by default) to store JavaScript that executes in the session of any user who later opens that view, including a Super Administrator on multisite..

Description

The Rank Math SEO WordPress plugin before 1.0.280 does not escape a stored redirection source value before outputting it in an administrative list view, allowing users who can manage redirections (Administrators by default) to store JavaScript that executes in the session of any user who later opens that view, including a Super Administrator on multisite.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
UnknownRank Math SEO< 1.0.280

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-104754?
The Rank Math SEO WordPress plugin before 1.0.280 does not escape a stored redirection source value before outputting it in an administrative list view, allowing users who can manage redirections (Administrators by default) to store JavaScript that executes in the session of any user who later opens that view, including a Super Administrator on multisite.
How severe is CVE-2026-104754?
CVE-2026-104754 has a CVSS score of 3.5/10 (LOW severity).
How do I fix CVE-2026-104754?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-104754?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST