SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-77783

LOW · CVSS 3.7 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Rank Math SEO plugin for WordPress prior to version 1.0.277 is vulnerable as it fails to ensure that the schema rendered for posts is publicly viewable, potentially exposing draft, pending, private, scheduled, and password-protected content to unauthenticated users. This could lead to unintended information disclosure, impacting the confidentiality of sensitive post data. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-77783
Severity
LOW
CVSS
3.7
EPSS
0.20%
WordPress

Original NVD Description

The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front end is publicly viewable, allowing unauthenticated visitors to disclose the schema and associated content of draft, pending, private, scheduled and password-protected posts.