
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12958 is an improper authorization vulnerability in the Rankology SEO and Analytics Tool plugin for WordPress, affecting all versions up to and including 2.0. The flaw allows authenticated attackers with Editor-level access or above to perform unauthorized modification of site data by injecting arbitrary header and footer code blocks via the rankology_code_block page. It was disclosed on January 7, 2026, with the CVE assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 2.7 (Low), reflecting the high privilege requirement and limited integrity impact (Wordfence, Red Hat CVE).
The root cause is an incorrect capability check (CWE-285: Improper Authorization) on the rankology_code_block admin page within the plugin. WordPress roles such as Editor, which are not intended to have administrative control over site-wide code injection, are incorrectly permitted to access and modify this functionality. An authenticated attacker with at least Editor-level credentials can send a crafted request to the vulnerable page to insert arbitrary JavaScript or HTML into the site's header and footer sections. A patch was committed to the WordPress plugin repository (changeset 3441084) (Wordfence, WordPress Trac).
Successful exploitation allows an authenticated Editor-level user to inject arbitrary code into the site's global header and footer, which is rendered on every page served to visitors. This could be leveraged to deliver malicious JavaScript (e.g., credential harvesting, cryptomining, or drive-by download scripts) to all site visitors, compromising visitor confidentiality and integrity. While the CVSS score reflects a low direct impact due to the high privilege requirement, the real-world consequence of persistent code injection across an entire WordPress site can be significant for end users (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-12958. The EPSS score is approximately 0.024%, indicating a very low probability of exploitation in the near term. The vulnerability requires authenticated access at the Editor level or above, significantly limiting the attack surface. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence, Red Hat CVE).
/wp-admin/) using the obtained credentials.rankology_code_block settings page within the Rankology SEO plugin admin interface, which incorrectly permits Editor-level users to modify header/footer code.rankology_code_block settings page; unexpected POST requests to the Rankology plugin admin page from non-administrator accounts.wp_options table) related to Rankology header/footer code blocks containing unexpected <script> tags or external URLs.wp_options for Rankology-related entries (e.g., options named rankology_header_code or rankology_footer_code) containing obfuscated or unexpected JavaScript payloads.Site administrators should update the Rankology SEO and Analytics Tool plugin to a version beyond 2.0, which includes the corrected capability check (patch committed as changeset 3441084 in the WordPress plugin repository). If an immediate update is not possible, restrict Editor-level and other non-administrator roles from accessing plugin settings pages using a role management plugin, or temporarily deactivate the Rankology plugin. Regularly audit the wp_options table for unexpected code in header/footer fields as a detection measure (Wordfence, WordPress Plugin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."