Description
The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires for the settings being changed, allowing users with the Editor role to modify site-wide core WordPress settings that are reserved to administrators.
Published: 2026-08-29
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Rank Math SEO plugin before 1.0.277 fails to verify that the user invoking the automatic SEO fix has the proper WordPress capability required for the specific settings it modifies. This allows any user with the Editor role, a role that normally lacks permission to change core WordPress configuration, to alter site‑wide settings that are reserved for administrators. The primary impact is a privilege escalation that can affect the confidentiality, integrity, and availability of the site by enabling unauthorized changes to essential WordPress settings.

Affected Systems

Affected product is the Rank Math SEO WordPress plugin, version earlier than 1.0.277. All WordPress installations that use this plugin and have Editor‑level users are potentially vulnerable. The vendor, Unknown:Rank Math SEO, released the fix in version 1.0.277, so any installations on that version or later are considered safe.

Risk and Exploitability

Although no EPSS score or CVSS score is provided, the lack of capability checks suggests the vulnerability can be exploited by any authenticated Editor user simply by triggering the fix‑site‑seo functionality. The omission of a check means the exploitability is high if an Editor role is present. Since the vulnerability does not require network exposure beyond the normal WordPress admin area, the attack vector is inferred to be local role‑based. The risk remains significant for sites with large numbers of Editor users, and the potential for misconfiguring core settings means the impact could be substantial.

Generated by OpenCVE AI on August 29, 2026 at 07:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Rank Math SEO plugin to version 1.0.277 or later to apply the vendor patch that adds capability verification.
  • Disable or remove the automatic SEO fix feature if the plugin cannot be updated, preventing the vulnerable routine from running.
  • Review user role capabilities to ensure that Editor users do not have unnecessary permissions for core settings, and restrict access to the fix‑site‑seo endpoint if possible.

Generated by OpenCVE AI on August 29, 2026 at 07:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Rank Math Seo
Rank Math Seo rank Math Seo
Wordpress
Wordpress wordpress
Vendors & Products Rank Math Seo
Rank Math Seo rank Math Seo
Wordpress
Wordpress wordpress

Sat, 29 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires for the settings being changed, allowing users with the Editor role to modify site-wide core WordPress settings that are reserved to administrators.
Title Rank Math SEO < 1.0.277 - Editor+ Core Settings Modification via fix-site-seo Ability
References

Subscriptions

Rank Math Seo Rank Math Seo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-29T06:00:22.804Z

Reserved: 2026-08-21T12:06:31.023Z

Link: CVE-2026-77786

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-29T06:17:44.250

Modified: 2026-08-29T06:17:44.250

Link: CVE-2026-77786

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T08:15:06Z

Weaknesses

No weakness.