All vulnerabilities
CVE-2026-77785 Low CVSS 2.7

Rank Math SEO - Author+ Non-Public Post Content Disclosure via Abilities API

Vendor Rank Math
Product Rank Math SEO (seo-by-rank-math)
Affected versions < 1.0.277
Weakness CWE-639 (Authorization Bypass Through User-Controlled Key)
CVSS vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Reported 2026-08-10
Disclosed 2026-08-31
Status Published
The plugin does not verify that the requesting user is authorized to access the specific post referenced in a request before returning it via the Abilities API, allowing users with the Author role or above to read the title, body, and SEO metadata of other users' non-public posts.

Impact

An authenticated user with Author-level access can enumerate and read private/draft post content and metadata belonging to other users — an information disclosure issue (IDOR) that could expose unpublished content, internal notes, or sensitive drafts before their intended release.