PatchSiren cyber security CVE debrief
CVE-2026-77786 Rank Math CVE debrief
The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires for the settings being changed, allowing users with the Editor role to modify site-wide core WordPress settings that are reserved to administrators. This issue may allow unauthorized changes to site configurations. The CVE record was published on 2026-08-29T06:17:44.250Z and has not been modified since then. Further review of plugin functionality and interaction with WordPress core settings is necessary. Limited information available; verify with vendor and monitor for updates. Additional verification is required to confirm affected scope and ensure accurate defensive measures. Administrators and users with Editor roles on WordPress sites using Rank Math SEO plugin version before 1.0.277 should verify site configurations and user privileges.
- Vendor
- Rank Math
- Product
- SEO WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-29
- Original CVE updated
- 2026-08-29
- Advisory published
- 2026-08-29
- Advisory updated
- 2026-08-29
Who should care
Administrators and users with Editor roles on WordPress sites using Rank Math SEO plugin version before 1.0.277 should verify site configurations and user privileges. Additionally, security teams and vulnerability management teams should review the issue to ensure proper defensive measures are in place. Monitoring of site-wide core WordPress settings for unauthorized changes is also recommended for all users of the affected plugin version.
Technical summary
The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires for the settings being changed, allowing users with the Editor role to modify site-wide core WordPress settings that are reserved to administrators. This issue may allow unauthorized changes to site configurations. Further review of plugin functionality and interaction with WordPress core settings is necessary.
Defensive priority
Administrators should verify WordPress site configurations and user roles to restrict Editor role privileges, and ensure Rank Math SEO plugin version 1.0.277 or later is installed.
Recommended defensive actions
- Verify WordPress site configurations and user roles to restrict Editor role privileges.
- Ensure Rank Math SEO plugin version 1.0.277 or later is installed.
- Monitor site-wide core WordPress settings for unauthorized changes.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires for the settings being changed. Limited information available; verify with vendor and monitor for updates. Additional verification is required to confirm affected scope and ensure accurate defensive measures.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77786 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77786
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77786 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77786
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/b0f3dfdb-9f0a-418c-9ce5-6a2b2b1f1b49/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.