CVE-2026-77788: Rank Math SEO < 1.0.277 - Author+ Arbitrary Post and User Metadata Overwrite via updateSchemas
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs to the object the user was authorised against, allowing users with the Author role and above to overwrite arbitrary post and user metadata, including that belonging to higher-privileged users.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rank Math SEO (WordPress plugin)to a version that resolves this vulnerability.Fixed in 1.0.277
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated WordPress user with the Author role or any higher-privileged role can exploit it.
What can a successful attacker modify?
They can overwrite arbitrary post and user metadata, including metadata associated with higher-privileged users.
Which installations are affected?
Rank Math SEO versions earlier than 1.0.277 are affected. Installations running version 1.0.277 or later are not identified as affected by the provided information.