Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 10 Oct 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Sat, 10 Oct 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-434 |
Sat, 10 Oct 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Rank Math SEO WordPress plugin before 1.0.280 does not correctly validate the type of a file uploaded through its settings import feature, allowing users with administrator-level access to upload a PHP file and achieve remote code execution. | |
| Title | Rank Math SEO < 1.0.280 - Admin+ Arbitrary File Upload to RCE via Settings Import | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-10T12:06:42.741Z
Reserved: 2026-10-02T12:14:27.318Z
Link: CVE-2026-104752
Updated: 2026-10-10T12:05:13.071Z
Status : Received
Published: 2026-10-10T06:16:39.383
Modified: 2026-10-10T12:16:43.973
Link: CVE-2026-104752
No data.
OpenCVE Enrichment
Updated: 2026-10-10T13:30:18Z
-
CWE-434
Unrestricted Upload of File with Dangerous Type