---
id: CVE-2026-104752
title: >-
  The Rank Math SEO  WordPress plugin before 1.0.280 does not correctly validate
  the type of a file uploaded through its settings import feature, allowing
  users with administrator-level access to upload a PHP file and achieve remote
  code e…
summary: >-
  The Rank Math SEO  WordPress plugin before 1.0.280 does not correctly validate
  the type of a file uploaded through its settings import feature, allowing
  users with administrator-level access to upload a PHP file and achieve remote
  code e…
severity: none
published: '2026-10-10'
updated: '2026-10-10'
sourceUpdated: '2026-10-10T06:16:39.383'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104752'
references:
  - url: 'https://wpscan.com/vulnerability/c7caaf99-5b0f-4935-8875-3a2b9c5ed782/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-10-10T06:24:42.859Z'
---

## Overview

The Rank Math SEO  WordPress plugin before 1.0.280 does not correctly validate the type of a file uploaded through its settings import feature, allowing users with administrator-level access to upload a PHP file and achieve remote code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
