Impact
Rank Math SEO, a WordPress plugin, contains a flaw in the updateSchemas routine that does not verify ownership of metadata rows before updating. Users with the Author role or higher can override arbitrary post and user metadata, including data belonging to users with higher privileges. This improper access control (CWE‑639) means that an attacker could potentially modify administrative data, although the description does not explicitly declare a privilege‑escalation outcome; that is inferred from the ability to overwrite higher‑privileged users' metadata.
Affected Systems
All installations of the Rank Math SEO plugin below version 1.0.277 on any WordPress site are vulnerable. The absence of vendor and product names beyond the plugin itself means the risk applies to every site that has not yet upgraded past the specified release.
Risk and Exploitability
The EPSS score of less than 1% indicates a low likelihood of exploitation in the wild, and the CVSS score of 4.9 classifies the vulnerability as medium severity. The flaw can be triggered by any user with an Author or higher role via the plugin’s updateSchemas endpoint, typically invoked during normal content or metadata editing. No publicly known exploits have surfaced, and the vulnerability is not listed in the CISA KEV catalog, suggesting that active exploitation is unlikely but the potential for metadata hijacking remains a concern.
OpenCVE Enrichment