← back
CVE-2026-77786mediumCWE-863

Rank Math SEO < 1.0.277 - Editor+ Core Settings Modification via fix-site-seo Ability

33Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 4.9epss 0.2%
exploitation probability
0.2%top 91% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires for the settings being changed, allowing users with the Editor role to modify site-wide core WordPress settings that are reserved to administrators.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Affected products
Unknown · Rank Math SEO
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.