ZeroHour

CVE-2026-78362

Unauthenticated Admin Takeover in SEO Flow by LupsOnline WordPress Plugin

CVSS 3.1
9.8 critical
EPSS
<1%p27
Published
()
Modified
AI analysis

SEO Flow by LupsOnline, a WordPress SEO plugin, does not correctly validate the credential supplied with its API requests, so unauthenticated requests are served as the administrator who configured the plugin (CWE-269, improper privilege management). Any unauthenticated attacker who can reach the plugin's API endpoints on a site where the plugin has been configured — its normal operating state — can exploit this with no credentials and no user interaction. Successful exploitation yields administrator-level access to the WordPress site, enabling complete takeover, consistent with the critical 9.8 CVSS score with high confidentiality, integrity, and availability impact. WordPress sites running SEO Flow by LupsOnline versions before 3.0.3 are affected. Exploitation has not been confirmed: no public proof-of-concept is known, the flaw is not in CISA's KEV, and EPSS estimates only about a 0.3% probability of exploitation within 30 days.

What to do: Upgrade to SEO Flow by LupsOnline 3.0.3 or later, the fixed version. Until patched, restrict or block unauthenticated access to the plugin's API endpoints at the web-application-firewall or web-server layer and monitor logs for requests to those endpoints. Because exploitation grants administrator-level access, also review the site for unexpected admin activity, new admin accounts, or unauthorized content/plugin changes.

Affected
LupsOnline SEO Flow (WordPress plugin)All versions before 3.0.3
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the SEO Flow by LupsOnline WordPress plugin before 3.0.3 to have been configured, which is its normal operating state.

Ecosystems
WordPress
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.