CVE-2026-78362
SEO Flow by LupsOnline 3.0.0 - 3.0.2 - Unauthenticated Privilege Escalation via API Key Authentication
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the SEO Flow by LupsOnline WordPress plugin before 3.0.3 to have been configured, which is its normal operating state.
| Vendor | unknown |
| Product | seo flow by lupsonline |
| Published | Sep 5, 2026 |
| Last Updated | Sep 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown seo flow by lupsonline
Be the first to know when new critical vulnerabilities affecting unknown seo flow by lupsonline are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / SEO Flow by LupsOnline
3.0.0 < 3.0.3
References
Credits
Naoki Kawahigashi WPScan