Medium severity4.9NVD Advisory· Published Sep 2, 2026· Updated Sep 2, 2026
CVE-2026-77788
CVE-2026-77788
Description
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs to the object the user was authorised against, allowing users with the Author role and above to overwrite arbitrary post and user metadata, including that belonging to higher-privileged users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.0.277
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.