WordPress Plugin Vulnerabilities

Rank Math SEO < 1.0.277 - Author+ Term Metadata Update and Cross-Object Post Title Overwrite via updateMetaBulk

Description

The plugin does not perform a capability check when bulk metadata updates target taxonomy terms, and reuses the supplied object identifier across object types, allowing users with the Author role and above to modify the SEO metadata of terms they cannot edit and to overwrite the titles of posts belonging to other users.

Proof of Concept

Affects Plugins

Fixed in 1.0.277

References

Classification

Type
NO AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
Mohammed Abd Alrahman
Submitter
Mohammed Abd Alrahman
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-08-31 (about 2 days ago)
Added
2026-08-31 (about 1 day ago)
Last Updated
2026-08-31 (about 1 day ago)

Other