CVE-2025-12714
5.3 MEDIUMThe Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capa...
Published: 2026-05-29 · Last updated: 2026-05-29
Severity and scoring
- CVSS
- 5.3 MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- CWE
- CWE-862
Description
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the update_site_editor_homepage function in all versions up to, and including, 1.0.271. This makes it possible for unauthenticated attackers to modify several plugin settings including homepage title, meta description, breadcrumbs label, and social media metadata, which can have severe impact on SEO rankings and display malicious content across all site pages where breadcrumbs are used.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2025-12714
- [Other]https://plugins.trac.wordpress.org/browser/seo-by-rank-math/trunk/includes/rest/class-rest-helper.php#L75
- [Other]https://plugins.trac.wordpress.org/browser/seo-by-rank-math/trunk/includes/rest/class-shared.php#L122
- [Other]https://plugins.trac.wordpress.org/browser/seo-by-rank-math/trunk/includes/rest/class-shared.php#L129
- [Other]https://plugins.trac.wordpress.org/browser/seo-by-rank-math/trunk/includes/rest/class-shared.php#L339
- [Other]https://plugins.trac.wordpress.org/changeset/3552223/seo-by-rank-math/trunk/includes/rest/class-rest-helper.php
- [Other]https://www.wordfence.com/threat-intel/vulnerabilities/id/dd072774-6f85-42de-a9d4-6826703ad839?source=cve
Related CVEs
Same CWE
- CVE-2026-6964 — The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7 (5.3 MEDIUM)
- CVE-2026-49775 — Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions (6.5 MEDIUM)
- CVE-2026-49070 — Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions (7.5 HIGH)
- CVE-2026-49065 — Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions (8.2 HIGH)
- CVE-2026-48887 — Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions (6.5 MEDIUM)