9.8

CVE-2026-78362

Exploit

SEO Flow by LupsOnline 3.0.0 - 3.0.2 - Unauthenticated Privilege Escalation via API Key Authentication

SEO Flow by LupsOnline 3.0.0 - 3.0.2 - Unauthenticated Privilege Escalation

The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the SEO Flow by LupsOnline WordPress plugin before 3.0.3 to have been configured, which is its normal operating state.
Mögliche Gegenmaßnahme
SEO Flow by LupsOnline: Update to version 3.0.3, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerUnknown
≫
Produkt SEO Flow by LupsOnline
Default Statusunaffected
Version 3.0.0
Version < 3.0.3
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt SEO Flow by LupsOnline
Version 3.0.0-3.0.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.042
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

https://wpscan.com/vulnerability/0833424b-1231-4a48-be90-13fe4edc60c9/
https://www.wordfence.com/threat-intel/vulnerabilities/id/82d408f2-9d72-465e-aa3d-eca4dab2af60
Third Party Advisory