Vulnerability Description
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs to the object the user was authorised against, allowing users with the Author role and above to overwrite arbitrary post and user metadata, including that belonging to higher-privileged users.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-77788?
CVE-2026-77788 is a vulnerability with a CVSS score of 4.9 (MEDIUM). The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs to the object the user was authorised against, allowing users with the Author role and ab...
How severe is CVE-2026-77788?
CVE-2026-77788 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-77788?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.