Junglewise Threat Intelligence

CVE-2026-77787: Rank Math SEO privilege escalation in bulk metadata update

CVE-2026-77787 · Severity: low · CVSS 2.7 · Published 2026-09-02

Technologies: Rank Math SEO. Vendors: Rank Math.

Executive brief

Rank Math SEO is a popular WordPress plugin that manages search engine optimization metadata for posts and taxonomy terms. The plugin fails to properly validate user permissions when bulk-updating metadata for taxonomy terms, allowing Authors and above to modify SEO metadata they should not have access to and overwrite post titles across the site. An attacker with an Author account can exploit this to deface post titles and inject malicious SEO data visible to all site visitors.

Technical details

The vulnerability is a broken access control issue (CWE-862) in the updateMetaBulk REST endpoint of Rank Math SEO before version 1.0.277. The endpoint fails to perform per-object capability checks when the objectType parameter is set to "term", and reuses the supplied object identifier across different object types (posts and terms) without validation. An authenticated user with Author role or higher can send a POST request to /rankmath/v1/updateMetaBulk with objectType="term" and an ID that matches both an existing post and a term ID to simultaneously modify term metadata and overwrite post titles. No additional preconditions beyond basic WordPress install defaults (like category ID 1 matching post ID 1) are required. The fix is available in version 1.0.277.

Affected products

  • Rank Math Rank Math SEO before 1.0.277

Timeline

  • 2026-08-31: disclosed
  • 2026-09-02: patched: Fixed in version 1.0.277

References

Related threats