CVE-2026-77784
Received Received - Intake

Rank Math SEO Metadata Manipulation via Author Role

Vulnerability report for CVE-2026-77784, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: WPScan

Description

The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object being modified before updating its SEO indexing metadata, allowing users with the Author role and above to alter that metadata on content, taxonomy terms and user profiles they do not own, and to remove other users' content from the site's sitemap and search engine index.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
rank_math seo_plugin to 1.0.277 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-77784 is an Insecure Direct Object Reference (IDOR) flaw in the Rank Math SEO WordPress plugin versions below 1.0.277. It allows users with Author privileges or higher to modify SEO indexing metadata on content, taxonomy terms, and user profiles they do not own. Attackers can also remove other users' content from the site's sitemap and search engine index.

Detection Guidance

To detect this vulnerability, check the installed version of the Rank Math SEO plugin. If it is below 1.0.277, the system is vulnerable. You can verify the version via WordPress admin panel under Plugins or by inspecting the plugin files on the server.

Impact Analysis

This vulnerability allows unauthorized users to alter SEO metadata on content they don't own, remove content from search engine indexes, and modify sitemaps. This could lead to content being hidden from search results or misrepresented in SEO rankings.

Compliance Impact

This vulnerability could potentially affect compliance with GDPR and HIPAA by allowing unauthorized users to modify or remove content from search engine indexes. Unauthorized changes to SEO metadata or removal of content may lead to data exposure or improper handling of sensitive information, which could violate privacy requirements under these regulations.

Mitigation Strategies

Immediately update the Rank Math SEO plugin to version 1.0.277 or later. This fixes the IDOR flaw and prevents unauthorized modifications to SEO metadata and sitemap content.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77784. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart