Executive brief
Rank Math SEO is a popular WordPress plugin that manages search engine optimization for websites. The plugin before version 1.0.277 fails to properly verify user permissions when making critical site-wide changes, allowing lower-level users (Editors) to modify settings that should only be accessible to administrators. This could let a compromised Editor account alter site structure, indexing settings, and SEO metadata across an entire site, disrupting availability and search visibility.
Technical details
The vulnerability is an authorization bypass in the `fix-site-seo` ability endpoint (CVE-2026-77786). The plugin does not check that the user holds the WordPress capabilities required for the underlying settings being modified, instead only checking the user's ability to invoke the fix itself. An authenticated user with the Editor role can call the `/wp-abilities/v1/abilities/rank-math/fix-site-seo/run` endpoint to modify core WordPress options (site description, permalink structure, blog visibility, rewrite rules, robots.txt, and SEO metadata) that are normally restricted to administrators. The vulnerability is reachable via REST API with application password authentication; no elevated privileges are needed to exploit it. The same bypass exists in the bundled MCP server endpoint. Fixed in version 1.0.277.
Affected products
- Rank Math SEO before 1.0.277
Timeline
- 2026-08-27: disclosed
- 2026-08-29: patched: Fixed in version 1.0.277