SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-77785

LOW · CVSS 2.7 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Rank Math SEO WordPress plugin prior to version 1.0.277 is vulnerable as it fails to properly verify user permissions, allowing users with the Author role and above to access the content and SEO metadata of non-public posts created by other users. This could lead to unauthorized disclosure of sensitive information, impacting user privacy and data confidentiality. WordPress site administrators and users of the Rank Math SEO plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-77785
Severity
LOW
CVSS
2.7
EPSS
0.18%
WordPress

Original NVD Description

The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to read the specific post referenced in a request before returning its content and SEO metadata, allowing users with the Author role and above to read the title, body and metadata of other users' non-public posts.