---
id: CVE-2026-77786
title: >-
  The Rank Math SEO  WordPress plugin before 1.0.277 does not check that the
  user requesting an automated SEO fix holds the capability WordPress itself
  requires for the settings being changed, allowing users with the Editor role
  to modify …
summary: >-
  The Rank Math SEO  WordPress plugin before 1.0.277 does not check that the
  user requesting an automated SEO fix holds the capability WordPress itself
  requires for the settings being changed, allowing users with the Editor role
  to modify …
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-863
published: '2026-08-29'
updated: '2026-08-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77786'
references:
  - url: 'https://wpscan.com/vulnerability/b0f3dfdb-9f0a-418c-9ce5-6a2b2b1f1b49/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00193
epssPercentile: 0.09259
ingestedAt: '2026-08-30T07:49:07.925Z'
---

## Overview

The Rank Math SEO  WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires for the settings being changed, allowing users with the Editor role to modify site-wide core WordPress settings that are reserved to administrators.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
