Impact
The Rank Math SEO WordPress plugin prior to version 1.0.277 releases schema data for posts without checking if the post is publicly viewable. Because the plugin does not enforce access control, unauthenticated visitors can retrieve the schema and full content of posts that are draft, pending, private, scheduled, or password protected. This results in a clear information‑disclosure vulnerability that allows attackers to read non‑public content and potentially harvest sensitive business or user data.
Affected Systems
The issue is present in all WordPress sites that have the Rank Math SEO plugin installed with a version older than 1.0.277. Affected installations include any vendor or developer using the Rank Math SEO plugin; the data lists no specific vendor variations. No further product or version details are provided, so the entire range of pre‑1.0.277 releases is considered at risk.
Risk and Exploitability
Because any unauthenticated visitor can trigger a normal page view, the attack vector is the public web front end; the vulnerability does not require authentication or elevated privileges. The CVSS score is 3.7, indicating a low impact on confidentiality and availability. The vulnerability is not listed in CISA’s KEV catalog and the EPSS score is < 1%, implying a very low predicted exploitation probability, but the lack of mitigation makes the risk significant for any installed plugin exposing non‑public content.
OpenCVE Enrichment