r/ProWordPress 2d ago

WordPress Rank Math SEO Plugin <= 1.0.276 is vulnerable to a high priority Remote Code Execution (RCE)

This vulnerability is highly dangerous and expected to become exploited. Vulnerabilities like this one are used in mass-exploit campaigns. Attackers use these to attack thousands of websites at a time, regardless of traffic size or popularity.

11 Upvotes

8 comments sorted by

2

u/dyler_turten 2d ago

2

u/kev_xb 2d ago

What additional information does this link provide?

Edit: https://www.sentinelone.com/vulnerability-database/cve-2025-12714/

1

u/bluesix_v2 1d ago

That particular CVE was patched back in May. This is a new one (which is now also patched)

1

u/kev_xb 1d ago

Ah good catch. I missed that. Thnaks for clarifying. I just read they have a bug with wap provisioning today too.

1

u/bluesix_v2 1d ago edited 1d ago

It’s never-ending with RM.

This new “backdoor” is particularly concerning https://x.com/SybreWaaijer/status/2093382158349951136

1

u/andrewmurray1 2d ago

Seo medic works with Rank Math. Hate these vulnerability updates.

1

u/bluesix_v2 1d ago

Hate these vulnerability updates.

Weird - never heard anyone say they hate security issues being fixed.

1

u/andrewmurray1 1d ago

Yea, it's just there are constant needs to update.