WordPress Plugin Vulnerabilities
Rank Math SEO < 1.0.277 - Unauthenticated Non-Public Post Schema and Content Disclosure
Description
The plugin does not verify that the post whose schema it renders on the front end is publicly viewable, allowing unauthenticated visitors to disclose the schema and associated content of draft, pending, private, scheduled and password-protected posts.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
IDOR
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Project Black
Submitter
Project Black
Submitter website
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-31 (about 3 days ago)
Added
2026-08-31 (about 2 days ago)
Last Updated
2026-08-31 (about 2 days ago)