The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the update_site_editor_homepage function in all versions up to, and including, 1.0.271. This makes it possible for unauthenticated attackers to modify several plugin settings including homepage title, meta description, breadcrumbs label, and social media metadata, which can have severe impact on SEO rankings and display malicious content across all site pages where breadcrumbs are used.
History

Fri, 29 May 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 29 May 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Rankmath
Rankmath rankmath Seo Ai Seo Tools To Dominate Seo Rankings
Wordpress
Wordpress wordpress
Vendors & Products Rankmath
Rankmath rankmath Seo Ai Seo Tools To Dominate Seo Rankings
Wordpress
Wordpress wordpress

Fri, 29 May 2026 10:30:00 +0000

Type Values Removed Values Added
Description The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the update_site_editor_homepage function in all versions up to, and including, 1.0.271. This makes it possible for unauthenticated attackers to modify several plugin settings including homepage title, meta description, breadcrumbs label, and social media metadata, which can have severe impact on SEO rankings and display malicious content across all site pages where breadcrumbs are used.
Title Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.271 - Missing Authorization to Unauthenticated Homepage Settings Modification
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-05-29T12:55:17.214Z

Reserved: 2025-11-04T19:56:00.630Z

Link: CVE-2025-12714

cve-icon Vulnrichment

Updated: 2026-05-29T12:55:13.761Z

cve-icon NVD

Status : Deferred

Published: 2026-05-29T11:16:15.700

Modified: 2026-05-29T13:09:05.450

Link: CVE-2025-12714

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T12:00:11Z