CVE-2026-77785: Rank Math SEO < 1.0.277 - Author+ Non-Public Post Content Disclosure via Abilities API
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to read the specific post referenced in a request before returning its content and SEO metadata, allowing users with the Author role and above to read the title, body and metadata of other users' non-public posts.
Affected Software
Event History
Frequently Asked Questions
Which users can exploit this issue?
A user with the WordPress Author role or any higher-privileged role can exploit it. The issue enables them to access non-public posts belonging to other users.
What information could be disclosed?
The affected API can return the referenced post's title, body content, and SEO metadata. The disclosed posts are non-public.
What should be checked during triage?
Identify installations running a Rank Math SEO version earlier than 1.0.277 and review whether Author-or-higher accounts exist. Also assess whether non-public posts from other users contain sensitive content or metadata.