CVE-2026-104752: CWE-434 Unrestricted Upload of File with Dangerous Type in Rank Math SEO
Description
The Rank Math SEO WordPress plugin before 1.0.280 does not correctly validate the type of a file uploaded through its settings import feature, allowing users with administrator-level access to upload a PHP file and achieve remote code execution.
CVSS v3.1
Score 7.2high
Affected software
Rank Math SEO
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-104752 is a vulnerability in the Rank Math SEO WordPress plugin (versions prior to 1.0.280) where the plugin fails to properly validate the type of files uploaded through its settings import feature. This flaw permits users with administrator privileges to upload files with dangerous types, such as PHP scripts, which can be executed remotely, potentially compromising the server.
Potential Impact
An attacker with administrator access can exploit this vulnerability to upload and execute arbitrary PHP code on the server hosting the WordPress site. This can lead to full system compromise, data theft, or further malicious activity.
Mitigation Recommendations
Upgrade the Rank Math SEO plugin to version 1.0.280 or later, where this vulnerability is fixed. Since the vulnerability exists in versions before 1.0.280, applying the official update is the recommended remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-10-02T12:14:27.318Z
- State
- PUBLISHED
Threat ID: 6ac9d5572cdf04f6560b02a8
Added to database: 10/10/2026, 06:04:07 UTC
Last enriched: 10/10/2026, 06:19:17 UTC
Last updated: 10/10/2026, 21:26:32 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.