SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-77784

LOW · CVSS 2.7 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Rank Math SEO WordPress plugin prior to version 1.0.277 is vulnerable due to insufficient verification of user permissions, allowing users with the Author role and above to modify SEO indexing metadata for content, taxonomy terms, and user profiles they do not own. This could lead to unauthorized alterations in search engine visibility and the removal of other users' content from the sitemap. WordPress site administrators and those managing user roles should prioritize this vulnerability to prevent potential misuse and maintain content integrity.

CVE
CVE-2026-77784
Severity
LOW
CVSS
2.7
EPSS
0.21%
WordPress

Original NVD Description

The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object being modified before updating its SEO indexing metadata, allowing users with the Author role and above to alter that metadata on content, taxonomy terms and user profiles they do not own, and to remove other users' content from the site's sitemap and search engine index.