WordPress security changelog
MEDIUM CVE-2026-77786 Deferred

Rank Math SEO Editors can change administrator-only WordPress settings

Rank Math SEO from 1.0.271 through 1.0.276 does not verify that a user requesting an automated SEO fix holds the capability required for each affected setting. An Editor can modify site-wide core WordPress settings reserved for Administrators.

CVE / CNA score 4.9 CVSS 3.1 · 134c704f-9b21-4f2e-91b3-4a467353bcc0
NVD score Pending NVD has not published its own CVSS assessment.
Component
Rank Math SEO
Plugin slug
seo-by-rank-math
Affected
1.0.271 to < 1.0.277
Safe version
1.0.277
Published
Aug 29, 2026
Weakness
CWE-863 — Incorrect Authorization

This CVE was published Aug 29, 2026 and is one of 26 known issues for this plugin.

Update, patch or deactivate.

Update to 1.0.277 or later and review core WordPress settings and Editor activity for unauthorized changes.

A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires for the settings being changed, allowing users with the Editor role to modify site-wide core WordPress settings that are reserved to administrators.

CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Primary and upstream sources