WordPress Plugin Vulnerabilities

Rank Math SEO < 1.0.277 - Unauthenticated Non-Public Post Schema and Content Disclosure

Description

The plugin does not verify that the post whose schema it renders on the front end is publicly viewable, allowing unauthenticated visitors to disclose the schema and associated content of draft, pending, private, scheduled and password-protected posts.

Proof of Concept

Affects Plugins

Fixed in 1.0.277

References

Classification

Type
IDOR
CWE
CVSS

Miscellaneous

Original Researcher
Project Black
Submitter
Project Black
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-08-31 (about 3 days ago)
Added
2026-08-31 (about 2 days ago)
Last Updated
2026-08-31 (about 2 days ago)

Other