SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77788

MEDIUM · CVSS 4.9 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Rank Math SEO plugin for WordPress prior to version 1.0.277 is vulnerable, allowing users with the Author role and above to overwrite arbitrary post and user metadata without proper authorization checks. This could lead to unauthorized changes to sensitive data, potentially affecting higher-privileged users. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-77788
Severity
MEDIUM
CVSS
4.9
EPSS
0.19%
WordPress

Original NVD Description

The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs to the object the user was authorised against, allowing users with the Author role and above to overwrite arbitrary post and user metadata, including that belonging to higher-privileged users.