Executive brief
Rank Math SEO is a popular WordPress plugin that manages search engine optimization metadata for posts and taxonomy terms. The plugin fails to properly validate user permissions when bulk-updating metadata for taxonomy terms, allowing Authors and above to modify SEO metadata they should not have access to and overwrite post titles across the site. An attacker with an Author account can exploit this to deface post titles and inject malicious SEO data visible to all site visitors.
Technical details
The vulnerability is a broken access control issue (CWE-862) in the updateMetaBulk REST endpoint of Rank Math SEO before version 1.0.277. The endpoint fails to perform per-object capability checks when the objectType parameter is set to "term", and reuses the supplied object identifier across different object types (posts and terms) without validation. An authenticated user with Author role or higher can send a POST request to /rankmath/v1/updateMetaBulk with objectType="term" and an ID that matches both an existing post and a term ID to simultaneously modify term metadata and overwrite post titles. No additional preconditions beyond basic WordPress install defaults (like category ID 1 matching post ID 1) are required. The fix is available in version 1.0.277.
Affected products
- Rank Math Rank Math SEO before 1.0.277
Timeline
- 2026-08-31: disclosed
- 2026-09-02: patched: Fixed in version 1.0.277