News : On August 26, 2026, Rank Math released version 1.0.277 of its WordPress SEO plugin, installed on more than 4 million sites. The official changelog announces a new “Support Agent” and “abilities for AI assistants to configure Rank Math's settings”. Two days later, developer Sybre Waaijer stated that this mechanism creates an administrator-level WordPress application password transmitted to the vendor (WordPress.org and Search Engine Journal, August 30, 2026).

Computer screen showing a WordPress administration dashboard with deliberately blurred text, in a dark office lit by a desk lamp

An SEO plugin can now open administrator-level access to your site for an AI agent, and open it without you noticing. That is the core of the Rank Math story. Part of the facts is confirmed by the vendor itself, in its own changelog. Another part is a public accusation the vendor has not answered. The distinction matters, and it should drive what you do in the next ten minutes.

What Rank Math confirms itself

The starting point is not a rumour: it is the plugin's public changelog, available on the Rank Math SEO listing on WordPress.org. Version 1.0.277, dated August 26, 2026, announces a support agent “that answers support questions anytime, directly from the plugin”, and, in the same list, “abilities for AI assistants to configure Rank Math's settings”. The same release also states that it “strengthened the security of the plugin”.

The most telling detail sits in the patch published the next day. Version 1.0.277.1, dated August 27, 2026, fixes a behaviour of “the Help & Support AI Assistant” that incorrectly displayed an HTTPS notice “when Application Passwords had been disabled by another plugin”. In other words: the vendor documents, in its own release notes, that its AI assistance feature depends on WordPress application passwords. That is not an outside inference, it is written in the changelog.

You need to know what an application password is to judge the scope. Introduced in WordPress 5.6, an application password is a separate credential meant for automated use, described in the integration guide published by the WordPress Core team. It cannot be used on the normal login screen, but it opens the site's REST API with the permissions of the account that generated it. Generated from an administrator account, it therefore authorises administrator actions: changing settings, creating or publishing content, managing plugins.

What is an accusation, and where it comes from

On August 28, 2026, Sybre Waaijer published a reading of that version's code on X. His wording is blunt: “Two days ago, Rank Math closed about a dozen security issues in 1.0.277. This plugin runs on over 4 million sites. In that same update, group.one (who also owns WP Rocket) now gets administrative privileges to your site.”

According to his analysis, picked up on August 30 by Search Engine Journal, opening the “Help & Support” section on a site connected to a free Rank Math account triggers the creation of an application password named “WAP - Rank Math Support Agent”. That password would be created before the terms-and-conditions box is even displayed, would not expire, and would not be revoked when the tab is closed.

One piece of context is essential here: Sybre Waaijer is the developer of The SEO Framework, an SEO plugin that competes directly with Rank Math. That does not disqualify his analysis, which concerns public code any developer can verify. It does require presenting it for what it is: a competitor's reading, not a neutral third party's finding. As of August 30, 2026, Search Engine Journal's coverage recorded neither a statement nor a denial from Rank Math or group.one.

Is your SEO stack opening doors you don't know about?

We audit your plugins, your access rights and your visibility in AI answers. Free, no strings attached.

Why this goes far beyond Rank Math

This story is the first mainstream case of a wider shift: AI agents are moving from readers to actors on your site. Until now, the question facing site owners was: which bots may read my pages? That is the debate we followed with Cloudflare's blocking of AI crawlers, and with the real-world adoption of the llms.txt specification. The question now arriving is of a different nature: which agents may write?

An agent that configures your SEO settings can change your title tags, your indexing directives, your redirects, your sitemap. Those are exactly the levers that determine whether your site is visible. What separates this from a classic security incident is that a bad change does not look like a hack: it looks like an unexplained traffic drop, three weeks later. It is the same traceability problem we raised about AI agent logs after the OpenAI Atlas shutdown: without a trail, there is no diagnosis.

What to do now

Three concrete actions, in order of priority.

  1. Check, site by site. In WordPress: Users → Profile → Application Passwords. Revoke any entry whose name starts with “WAP” if you did not knowingly create it. Budget under a minute per site. This has no negative effect on your rankings.
  2. Audit your administrator accounts. The described mechanism only triggers from an administrator account. Many small-business sites carry three to five administrator accounts that should be editors. Cutting that number mechanically reduces the exposed surface, whichever plugin is involved.
  3. Treat release notes as a security document. What made this story documentable was not an expensive audit: it was reading a public changelog. When an update announces that an AI assistant can “configure settings”, that is an architecture decision, not a convenience improvement.

The limits of what we know

Several points remain open, and it would be dishonest to present them otherwise. The vendor's intent is not established: the most favourable reading is a technical support feature with poorly framed consent, which is very different from deliberate collection. No actual abuse, no unsolicited change to any site, has been publicly reported to date. The real number of sites where the password was created is unknown: it requires version 1.0.277, a connected Rank Math account and someone opening the support screen. The 4 million figure is the plugin's active installation count, not the count of affected sites. Finally, this article does not cover the WPForms case, raised in the same context by several observers, which rests on a distinct mechanism.

Frequently asked questions

How do I know if my site is affected?

Open your WordPress admin, go to Users, then Profile, then the Application Passwords section. If an entry whose name starts with “WAP” is listed, it was created. You can revoke it from that screen. It takes under a minute per site and has no effect on your search rankings.

Should I uninstall Rank Math?

Nothing justifies that at this stage. No actual abuse of this mechanism has been publicly reported, and the official changelog documents the feature itself. Revoking the application password and watching for vendor statements is a proportionate response. Uninstalling an SEO plugin in a hurry usually causes more damage than the risk being avoided.

Is an application password the same as an administrator password?

No, but the practical effect is close. It is a separate credential created for automated use, and it cannot be used on the normal login screen. It does however grant access to the WordPress REST API with the permissions of the account that generated it. Generated from an administrator account, it therefore enables administrator-level actions.

Has Rank Math responded?

No public statement from Rank Math or group.one was recorded in the Search Engine Journal coverage published on August 30, 2026. Without a vendor response, the intent behind this code is not established, and what is available remains an accusation supported by a reading of the code, not a fact verified on both sides.

The Cicéro take

Our reading: the problem is not that a vendor wired an AI into its support, it is that consent arrived after the credential was created rather than before. The order of operations is the whole difference between a feature and an access grab. For small businesses, the useful lesson is not to distrust Rank Math specifically: it is to accept that “which AI agents can write to my site?” has just joined the list of basic checks, alongside backups. And in 2026, that question is no longer one for your host alone: it applies to every single plugin you run.

Sources

Alexis Dollé, founder of Cicéro
Alexis Dollé
CEO & Founder

Growth and SEO & GEO content strategist, I founded Cicéro to help businesses build lasting organic visibility : on Google and in AI-generated answers alike. Every piece of content we produce is designed to convert, not just to exist.

LinkedIn