Description
The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied object identifier across object types, allowing users with the Author role and above to modify the SEO metadata of terms they cannot edit and to overwrite the titles of posts belonging to other users.
Published: 2026-09-02
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Metadata Modification and Post Title Overwrite
Action: Immediate Patch
AI Analysis

Impact

The Rank Math SEO WordPress plugin before version 1.0.277 performs a bulk metadata update via the updateMetaBulk function without verifying that the caller has the required privileges. The function reuses the supplied object identifier across multiple object types, allowing an authenticated user with the Author role or higher to modify SEO metadata for taxonomy terms that they are normally not allowed to edit and to overwrite the titles of posts belonging to other users. This flaw can compromise the integrity of post content and could be leveraged to manipulate search engine optimization settings or to hide or vandalize content. The vulnerability is a classic example of Improper Access Control as it permits privileged users to affect resources beyond their scope.

Affected Systems

Any WordPress installation running Rank Math SEO plugin with a version older than 1.0.277 is affected. The plugin may be installed on any site that relies on Rank Math for SEO management, including blogs, corporate websites, and e‑commerce storefronts. Users with the Author role or higher (including Editors, Admins, and Super Admins in multisite) are the primary threat actors; any site with a full administrative user base that cannot be constrained is at risk.

Risk and Exploitability

The CVSS score of 2.7 indicates low severity, and EPSS is not available, so a precise quantitative risk cannot be assigned. The flaw is not listed in the CISA KEV catalog and has no publicly known exploits at this time. However, the low barrier to exploitation – simply logging in as an Author or higher and invoking the updateMetaBulk endpoint – means that the potential for immediate disruption exists on any unpatched site. The impact is limited to data integrity (metadata and post titles) and does not provide remote code execution or privilege escalation. Nonetheless, the cost of a post title overwrite can be high in e‑commerce or legal compliance contexts, and unauthorized metadata changes can degrade SEO performance and trust.

Generated by OpenCVE AI on September 2, 2026 at 13:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Rank Math SEO to version 1.0.277 or newer to remove the missing capability check
  • If an immediate update is not possible, restrict the Author role and above from using the bulk metadata update feature by disabling or removing the updateMetaBulk endpoint through custom code or a security plugin
  • Apply role-based access control to ensure that only administrators possess the capability to edit term metadata and post titles

Generated by OpenCVE AI on September 2, 2026 at 13:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Rank Math Seo
Rank Math Seo rank Math Seo
Wordpress
Wordpress wordpress
Vendors & Products Rank Math Seo
Rank Math Seo rank Math Seo
Wordpress
Wordpress wordpress

Wed, 02 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied object identifier across object types, allowing users with the Author role and above to modify the SEO metadata of terms they cannot edit and to overwrite the titles of posts belonging to other users.
Title Rank Math SEO < 1.0.277 - Author+ Term Metadata Update and Cross-Object Post Title Overwrite via updateMetaBulk
References

Subscriptions

Rank Math Seo Rank Math Seo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-02T10:45:56.929Z

Reserved: 2026-08-21T12:06:32.625Z

Link: CVE-2026-77787

cve-icon Vulnrichment

Updated: 2026-09-02T10:12:03.714Z

cve-icon NVD

Status : Deferred

Published: 2026-09-02T06:17:17.870

Modified: 2026-09-03T17:50:37.690

Link: CVE-2026-77787

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T13:30:05Z

Weaknesses