All vulnerabilities
CVE-2026-77785
Low
CVSS 2.7
Rank Math SEO - Author+ Non-Public Post Content Disclosure via Abilities API
| Vendor | Rank Math |
|---|---|
| Product | Rank Math SEO (seo-by-rank-math) |
| Affected versions | < 1.0.277 |
| Weakness | CWE-639 (Authorization Bypass Through User-Controlled Key) |
| CVSS vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
| Reported | 2026-08-10 |
| Disclosed | 2026-08-31 |
| Status | Published |
The plugin does not verify that the requesting user is authorized to access the specific post referenced in a request before returning it via the Abilities API, allowing users with the Author role or above to read the title, body, and SEO metadata of other users' non-public posts.
Impact
An authenticated user with Author-level access can enumerate and read private/draft post content and metadata belonging to other users — an information disclosure issue (IDOR) that could expose unpublished content, internal notes, or sensitive drafts before their intended release.