CVE-2026-77783
Rank Math SEO < 1.0.277 - Unauthenticated Non-Public Post Schema and Content Disclosure
LOW 3.7EPSS 0.2%
The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front end is publicly viewable, allowing unauthenticated visitors to disclose the schema and associated content of draft, pending, private, scheduled and password-protected posts.
- Affected
- Rank Math SEO
- CVSS v3.1 CNA
- 3.7 LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N - EPSS
- 0.20% chance of exploitation in the next 30 days, 9th percentile
- Published
- 2026-09-02