๐Ÿ” CVE Alert

CVE-2026-78362

CRITICAL 9.8

SEO Flow by LupsOnline 3.0.0 - 3.0.2 - Unauthenticated Privilege Escalation via API Key Authentication

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the SEO Flow by LupsOnline WordPress plugin before 3.0.3 to have been configured, which is its normal operating state.

Vendor unknown
Product seo flow by lupsonline
Published Sep 5, 2026
Last Updated Sep 6, 2026
Stay Ahead of the Next One

Get instant alerts for unknown seo flow by lupsonline

Be the first to know when new critical vulnerabilities affecting unknown seo flow by lupsonline are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / SEO Flow by LupsOnline
3.0.0 < 3.0.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/0833424b-1231-4a48-be90-13fe4edc60c9/

Credits

Naoki Kawahigashi WPScan