CVE-2026-77788 PUBLISHED

Rank Math SEO < 1.0.277 - Author+ Arbitrary Post and User Metadata Overwrite via updateSchemas

Assigner: WPScan
Reserved: 21.08.2026 Published: 02.09.2026 Updated: 02.09.2026

The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs to the object the user was authorised against, allowing users with the Author role and above to overwrite arbitrary post and user metadata, including that belonging to higher-privileged users.

Product Status

Vendor Unknown
Product Rank Math SEO
Versions Default: unaffected
  • affected from 1.0.48 to 1.0.277 (excl.)

Credits

  • Usama Arshad finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE