CVE-2026-77784: Rank Math SEO < 1.0.277 - Author+ Robots and Pillar Content Meta Update on Non-Owned Objects via mark_page_as
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object being modified before updating its SEO indexing metadata, allowing users with the Author role and above to alter that metadata on content, taxonomy terms and user profiles they do not own, and to remove other users' content from the site's sitemap and search engine index.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/rank-math-seoto a version that resolves this vulnerability.Fixed in 1.0.277
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user with the Author role or higher can exploit it. The affected plugin fails to confirm that the user is permitted to edit the targeted post, taxonomy term, or user profile.
What can an attacker change?
An attacker can alter SEO indexing metadata, including robots and pillar-content metadata, on objects they do not own. They can use this to remove other users' content from the site's sitemap and search-engine index.
Which installations are affected?
Rank Math SEO versions before 1.0.277 are affected. The issue applies where users with Author-level or greater access can authenticate to the WordPress site.
What should be done if the plugin cannot be updated immediately?
Restrict or remove Author-and-higher access for untrusted users until an update can be applied. Review SEO metadata, sitemap inclusion, and search-indexing settings on posts, taxonomy terms, and user profiles for unauthorized changes.