CVE-2026-77784

The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object being modified before updating its SEO indexing metadata, allowing users with the Author role and above to alter that metadata on content, taxonomy terms and user profiles they do not own, and to remove other users' content from the site's sitemap and search engine index.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 06:17

Updated : 2026-09-03 17:50


NVD link : CVE-2026-77784

Mitre link : CVE-2026-77784

CVE.ORG link : CVE-2026-77784


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key