Description
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front end is publicly viewable, allowing unauthenticated visitors to disclose the schema and associated content of draft, pending, private, scheduled and password-protected posts.
Published: 2026-09-02
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted disclosure of non‑public post content and schema
Action: Update plugin
AI Analysis

Impact

The Rank Math SEO WordPress plugin prior to version 1.0.277 releases schema data for posts without checking if the post is publicly viewable. Because the plugin does not enforce access control, unauthenticated visitors can retrieve the schema and full content of posts that are draft, pending, private, scheduled, or password protected. This results in a clear information‑disclosure vulnerability that allows attackers to read non‑public content and potentially harvest sensitive business or user data.

Affected Systems

The issue is present in all WordPress sites that have the Rank Math SEO plugin installed with a version older than 1.0.277. Affected installations include any vendor or developer using the Rank Math SEO plugin; the data lists no specific vendor variations. No further product or version details are provided, so the entire range of pre‑1.0.277 releases is considered at risk.

Risk and Exploitability

Because any unauthenticated visitor can trigger a normal page view, the attack vector is the public web front end; the vulnerability does not require authentication or elevated privileges. The CVSS score is 3.7, indicating a low impact on confidentiality and availability. The vulnerability is not listed in CISA’s KEV catalog and the EPSS score is < 1%, implying a very low predicted exploitation probability, but the lack of mitigation makes the risk significant for any installed plugin exposing non‑public content.

Generated by OpenCVE AI on September 2, 2026 at 15:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Rank Math SEO plugin to version 1.0.277 or later, which addresses the access‑control check.
  • If an immediate upgrade is not possible, disable the Rank Math SEO plugin or remove its output for non‑logged‑in users until a fix is applied.
  • Perform a comprehensive review of the website’s content exposure settings and other plugins to ensure no similar access‑control gaps exist before re‑enabling any SEO‑related features.

Generated by OpenCVE AI on September 2, 2026 at 15:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Wed, 02 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Rank Math Seo
Rank Math Seo rank Math Seo
Wordpress
Wordpress wordpress
Weaknesses CWE-200
CWE-284
Vendors & Products Rank Math Seo
Rank Math Seo rank Math Seo
Wordpress
Wordpress wordpress

Wed, 02 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front end is publicly viewable, allowing unauthenticated visitors to disclose the schema and associated content of draft, pending, private, scheduled and password-protected posts.
Title Rank Math SEO < 1.0.277 - Unauthenticated Non-Public Post Schema and Content Disclosure
References

Subscriptions

Rank Math Seo Rank Math Seo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-02T10:45:57.371Z

Reserved: 2026-08-21T12:06:17.082Z

Link: CVE-2026-77783

cve-icon Vulnrichment

Updated: 2026-09-02T10:12:13.240Z

cve-icon NVD

Status : Deferred

Published: 2026-09-02T06:17:17.567

Modified: 2026-09-03T17:50:37.690

Link: CVE-2026-77783

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T15:45:04Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key