CVE-2026-77783
Received Received - Intake

Schema Exposure in Rank Math SEO WordPress Plugin

Vulnerability report for CVE-2026-77783, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: WPScan

Description

The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front end is publicly viewable, allowing unauthenticated visitors to disclose the schema and associated content of draft, pending, private, scheduled and password-protected posts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
rank_math seo_plugin to 1.0.277 (exc)
rank_math seo to 1.0.277 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Rank Math SEO WordPress plugin before version 1.0.277 has a flaw where it does not check if a post is publicly viewable before rendering its schema on the front end. This allows unauthenticated users to access the schema and content of posts that are not meant to be public, such as drafts, pending posts, private posts, scheduled posts, or password-protected posts.

Detection Guidance

To detect this vulnerability, check the version of the Rank Math SEO plugin installed on your WordPress site. If it is below 1.0.277, the site is vulnerable. You can verify the version by inspecting the plugin files or using WordPress admin panel.

Impact Analysis

This vulnerability could allow unauthorized users to view sensitive or unpublished content on your WordPress site. If you have private drafts, scheduled posts, or password-protected content, attackers could access this information without authentication. It may also expose metadata or schema details that could be used for further attacks.

Compliance Impact

This vulnerability could lead to non-compliance with data protection regulations like GDPR or HIPAA if it exposes personally identifiable information (PII) or sensitive health data stored in drafts, private posts, or password-protected content. Unauthorized access to such data violates confidentiality requirements.

Mitigation Strategies

Immediately update the Rank Math SEO plugin to version 1.0.277 or later. This version includes the fix for the vulnerability. Ensure automatic updates are enabled for critical plugins to prevent similar issues in the future.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77783. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart