SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77782

MEDIUM · CVSS 5.3 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Rank Math SEO plugin for WordPress prior to version 1.0.277.1 is vulnerable as it fails to verify if a post is password-protected before utilizing its content for generating SEO metadata. This oversight allows unauthenticated users to access and read the content of protected posts, potentially exposing sensitive information. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of unauthorized content exposure.

CVE
CVE-2026-77782
Severity
MEDIUM
CVSS
5.3
EPSS
0.25%
WordPress

Original NVD Description

The Rank Math SEO WordPress plugin before 1.0.277.1 does not check whether a post is password protected before using its content to build publicly generated SEO metadata, allowing unauthenticated users to read the content of password-protected posts.