ZeroHour

CVE-2026-77786

CVSS 3.1
4.9 medium
EPSS
<1%p9
Published
()
Modified
Description

The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires for the settings being changed, allowing users with the Editor role to modify site-wide core WordPress settings that are reserved to administrators.

Ecosystems
WordPress
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.