Executive brief
Rank Math SEO is a WordPress plugin that optimizes site content for search engines. The plugin's REST API endpoints fail to verify user permissions before returning private post content and metadata, allowing any Author-level user to view other authors' confidential posts, drafts, and scheduled content that should be hidden from them.
Technical details
The vulnerability is an Insecure Direct Object Reference (IDOR) / broken access control flaw in the Rank Math SEO plugin's Abilities API endpoints (/wp-abilities/v1/abilities/rank-math/*). The affected endpoints—analyze-post-content, get-post-seo-meta, and get-post-schema—accept a post_id parameter but do not verify that the authenticated user has permission to read that specific post before returning its title, body, SEO metadata, and schema. The vulnerability requires WordPress 6.9+ (where the Abilities API is core) and affects users with the Author role and above. An authenticated Author can enumerate sequential post IDs and retrieve private, scheduled, and trashed posts belonging to other authors. The plugin was patched in version 1.0.277.
Affected products
- Rank Math SEO before 1.0.277
Timeline
- 2026-08-31: disclosed
- 2026-08-31: patched: fixed in version 1.0.277
- 2026-09-02: advisory