Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 10 Oct 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-434 |
Sat, 10 Oct 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Rank Math SEO WordPress plugin before 1.0.280 does not correctly validate the type of a file uploaded through its settings import feature, allowing users with administrator-level access to upload a PHP file and achieve remote code execution. | |
| Title | Rank Math SEO < 1.0.280 - Admin+ Arbitrary File Upload to RCE via Settings Import | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-10T06:00:07.588Z
Reserved: 2026-10-02T12:14:27.318Z
Link: CVE-2026-104752
No data.
Status : Received
Published: 2026-10-10T06:16:39.383
Modified: 2026-10-10T06:16:39.383
Link: CVE-2026-104752
No data.
OpenCVE Enrichment
Updated: 2026-10-10T09:00:03Z