Description
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs to the object the user was authorised against, allowing users with the Author role and above to overwrite arbitrary post and user metadata, including that belonging to higher-privileged users.
Published:
2026-09-02
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 02 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs to the object the user was authorised against, allowing users with the Author role and above to overwrite arbitrary post and user metadata, including that belonging to higher-privileged users. | |
| Title | Rank Math SEO < 1.0.277 - Author+ Arbitrary Post and User Metadata Overwrite via updateSchemas | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-02T06:00:19.809Z
Reserved: 2026-08-21T12:06:34.124Z
Link: CVE-2026-77788
No data.
Status : Received
Published: 2026-09-02T06:17:17.970
Modified: 2026-09-02T06:17:17.970
Link: CVE-2026-77788
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.