Low severity2.7NVD Advisory· Published Sep 2, 2026· Updated Sep 2, 2026
CVE-2026-77787
CVE-2026-77787
Description
The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied object identifier across object types, allowing users with the Author role and above to modify the SEO metadata of terms they cannot edit and to overwrite the titles of posts belonging to other users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.0.277
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.