Junglewise Threat Intelligence

CVE-2026-77786: Rank Math SEO privilege escalation in site settings modification

CVE-2026-77786 · Severity: medium · CVSS 4.9 · Published 2026-08-29

Technologies: Rank Math SEO. Vendors: Rank Math.

Executive brief

Rank Math SEO is a popular WordPress plugin that manages search engine optimization for websites. The plugin before version 1.0.277 fails to properly verify user permissions when making critical site-wide changes, allowing lower-level users (Editors) to modify settings that should only be accessible to administrators. This could let a compromised Editor account alter site structure, indexing settings, and SEO metadata across an entire site, disrupting availability and search visibility.

Technical details

The vulnerability is an authorization bypass in the `fix-site-seo` ability endpoint (CVE-2026-77786). The plugin does not check that the user holds the WordPress capabilities required for the underlying settings being modified, instead only checking the user's ability to invoke the fix itself. An authenticated user with the Editor role can call the `/wp-abilities/v1/abilities/rank-math/fix-site-seo/run` endpoint to modify core WordPress options (site description, permalink structure, blog visibility, rewrite rules, robots.txt, and SEO metadata) that are normally restricted to administrators. The vulnerability is reachable via REST API with application password authentication; no elevated privileges are needed to exploit it. The same bypass exists in the bundled MCP server endpoint. Fixed in version 1.0.277.

Affected products

  • Rank Math SEO before 1.0.277

Timeline

  • 2026-08-27: disclosed
  • 2026-08-29: patched: Fixed in version 1.0.277

References