PT-2026-84621 · WordPress · Rank Math Seo
CVE-2026-77787
·
Published
2026-09-02
·
Updated
2026-09-02
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Rank Math SEO WordPress plugin versions prior to 1.0.277
Description
Insufficient capability checks during bulk metadata updates targeting taxonomy terms allow users with the Author role or higher to modify SEO metadata for terms they lack permission to edit. Additionally, the reuse of supplied object identifiers across different object types enables these users to overwrite titles of posts belonging to other users.
Recommendations
Update Rank Math SEO WordPress plugin to version 1.0.277 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rank Math Seo