Description
The Rank Math SEO WordPress plugin before 1.0.277.1 does not check whether a post is password protected before using its content to build publicly generated SEO metadata, allowing unauthenticated users to read the content of password-protected posts.
Published: 2026-09-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

A flaw in the Rank Math SEO WordPress plugin allows unauthenticated visitors to obtain the full content of password‑protected posts by exploiting the way the plugin builds SEO metadata. The plugin does not verify whether a post is password‑protected before using its content, so an attacker can read what should be hidden content without authenticating or bypassing any security controls. This results in a breach of confidentiality.

Affected Systems

The vulnerability affects the Rank Math SEO plugin for WordPress, specifically versions older than 1.0.277.1. Any site running a pre‑1.0.277.1 installation is susceptible.

Risk and Exploitability

Because the attack requires no authentication and follows a standard HTTP request to the public site, the risk is moderate for privacy, but the exploitation probability is unknown as EPSS data is not available and the vulnerability is not listed in KEV. Attackers can read the disclosed content remotely, but there is no known privilege escalation or code execution path. The CVSS score of 5.3 indicates moderate severity, so organizations should consider the confidentiality impact significant, especially for sensitive or proprietary posts.

Generated by OpenCVE AI on September 2, 2026 at 13:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Rank Math SEO to 1.0.277.1 or later.
  • If an upgrade cannot be performed immediately, temporarily disable the plugin’s SEO metadata generation for password‑protected posts until a patch is issued.
  • Continuously monitor public pages for unexpected disclosure of sensitive content following the update.

Generated by OpenCVE AI on September 2, 2026 at 13:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Rank Math Seo
Rank Math Seo rank Math Seo
Wordpress
Wordpress wordpress
Vendors & Products Rank Math Seo
Rank Math Seo rank Math Seo
Wordpress
Wordpress wordpress

Wed, 02 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Wed, 02 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Rank Math SEO WordPress plugin before 1.0.277.1 does not check whether a post is password protected before using its content to build publicly generated SEO metadata, allowing unauthenticated users to read the content of password-protected posts.
Title Rank Math SEO < 1.0.277.1 - Unauthenticated Password-Protected Post Content Disclosure via Post Metadata and llms.txt
References

Subscriptions

Rank Math Seo Rank Math Seo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-02T10:45:57.513Z

Reserved: 2026-08-21T12:06:14.893Z

Link: CVE-2026-77782

cve-icon Vulnrichment

Updated: 2026-09-02T10:12:16.739Z

cve-icon NVD

Status : Deferred

Published: 2026-09-02T06:17:17.463

Modified: 2026-09-03T17:50:37.690

Link: CVE-2026-77782

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T13:30:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor