{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-77785","assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","state":"PUBLISHED","assignerShortName":"WPScan","dateReserved":"2026-08-21T12:06:20.673Z","datePublished":"2026-09-02T06:00:19.466Z","dateUpdated":"2026-09-02T10:45:57.077Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan","dateUpdated":"2026-09-02T06:00:19.466Z"},"title":"Rank Math SEO < 1.0.277 - Author+ Non-Public Post Content Disclosure via Abilities API","problemTypes":[{"descriptions":[{"description":"CWE-639 Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}]}],"affected":[{"vendor":"Unknown","product":"Rank Math SEO","versions":[{"status":"affected","versionType":"semver","version":"1.0.272","lessThan":"1.0.277"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"The Rank Math SEO  WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to read the specific post referenced in a request before returning its content and SEO metadata, allowing users with the Author role and above to read the title, body and metadata of other users' non-public posts."}],"references":[{"url":"https://wpscan.com/vulnerability/7cf8aa8a-7ac2-4e70-a7af-3f23e4ac1824/","tags":["exploit","vdb-entry","technical-description"]}],"credits":[{"lang":"en","value":"Mohammed Abd Alrahman","type":"finder"},{"lang":"en","value":"WPScan","type":"coordinator"}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"WPScan CVE Generator"}},"adp":[{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":2.7,"attackVector":"NETWORK","baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"NONE","privilegesRequired":"HIGH","confidentialityImpact":"LOW"}},{"other":{"type":"ssvc","content":{"id":"CVE-2026-77785","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2026-09-02T10:34:13.999789Z"}}}],"problemTypes":[{"descriptions":[{"lang":"en","type":"CWE","cweId":"CWE-639","description":"CWE-639 Authorization Bypass Through User-Controlled Key"}]}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-02T10:45:57.077Z"}}]}}