CVE-2026-77782
The Rank Math SEO WordPress plugin before 1.0.277.1 does not check whether a post is password protected before using its content to build p
CVSS
5.3
Medio
EPSS
0.2%
p5
KEV
—
Exploit Today
2
0-100
Publicado: 2 sept 2026 · Última mod.: 2 sept 2026 · CWE-200
Sin historial EPSS suficiente todavía.
The Rank Math SEO WordPress plugin before 1.0.277.1 does not check whether a post is password protected before using its content to build publicly generated SEO metadata, allowing unauthenticated users to read the content of password-protected posts.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-846584.3 MED—
——0Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowing attackers able to submit certain forms to read that configuration.19hCVE-2026-811995.3 MED0.7%
——0The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's learning statistics, allowing unauthenticated attackers to disclose the course counts, points, certificates, quiz and assignment totals of any registered user.1dCVE-2026-811975.3 MED4.1%
——1The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not restrict access to a REST route that lists an author's courses, nor does it filter that listing by publication status, allowing unauthenticated users to read the titles and IDs of unpublished (draft, pending and private) courses.1dCVE-2026-811955.3 MED4.1%
——1The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning per-student course enrollment and progress data, allowing unauthenticated attackers to disclose the enrolled courses and learning progress of any registered user.1dCVE-2026-781515.3 MED4.1%
——1The FormLayer WordPress plugin before 1.0.9 does not perform any authorization check before returning a form's full stored configuration in the response to its public submission handler, allowing unauthenticated users to disclose notification recipient addresses, confirmation redirect targets and integration settings, including those of unpublished forms.1dCVE-2026-192515.3 MED4.4%
——1The Ultimate Member WordPress plugin before 2.13.0 does not check whether a comment has been approved, or whether the profile it belongs to is private, before returning profile activity to unauthenticated visitors, allowing them to read the content of comments still awaiting moderation.1d