Impact
A flaw in the Rank Math SEO WordPress plugin allows unauthenticated visitors to obtain the full content of password‑protected posts by exploiting the way the plugin builds SEO metadata. The plugin does not verify whether a post is password‑protected before using its content, so an attacker can read what should be hidden content without authenticating or bypassing any security controls. This results in a breach of confidentiality.
Affected Systems
The vulnerability affects the Rank Math SEO plugin for WordPress, specifically versions older than 1.0.277.1. Any site running a pre‑1.0.277.1 installation is susceptible.
Risk and Exploitability
Because the attack requires no authentication and follows a standard HTTP request to the public site, the risk is moderate for privacy, but the exploitation probability is unknown as EPSS data is not available and the vulnerability is not listed in KEV. Attackers can read the disclosed content remotely, but there is no known privilege escalation or code execution path. The CVSS score of 5.3 indicates moderate severity, so organizations should consider the confidentiality impact significant, especially for sensitive or proprietary posts.
OpenCVE Enrichment