SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-77787

LOW · CVSS 2.7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Rank Math SEO plugin for WordPress prior to version 1.0.277 is vulnerable due to a lack of capability checks during bulk metadata updates, enabling users with the Author role and higher to alter SEO metadata for taxonomy terms and overwrite post titles belonging to other users. This could lead to unauthorized modifications of content visibility and SEO performance. WordPress site administrators, especially those using the Rank Math SEO plugin, should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-77787
Severity
LOW
CVSS
2.7
EPSS
0.17%
WordPress

Original NVD Description

The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied object identifier across object types, allowing users with the Author role and above to modify the SEO metadata of terms they cannot edit and to overwrite the titles of posts belonging to other users.