SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77786

MEDIUM · CVSS 4.9 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-29 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Rank Math SEO plugin for WordPress prior to version 1.0.277 is vulnerable as it fails to properly validate user permissions, allowing users with the Editor role to alter critical site-wide settings typically restricted to administrators. This oversight could lead to unauthorized changes that compromise site integrity and security. WordPress site administrators and users of the Rank Math SEO plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-77786
Severity
MEDIUM
CVSS
4.9
EPSS
0.19%
WordPress

Original NVD Description

The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires for the settings being changed, allowing users with the Editor role to modify site-wide core WordPress settings that are reserved to administrators.