CVE-2026-78362
9.8LupsOnline · SEO Flow
The SEO Flow WordPress plugin contains an improper privilege management vulnerability that allows unauthenticated attackers to gain administrative site access via crafted API requests.
Executive summary
A critical vulnerability in the SEO Flow WordPress plugin allows unauthenticated attackers to perform a full account takeover of the affected site.
Vulnerability
The plugin fails to correctly validate credentials within its API requests, which allows an unauthenticated user to impersonate the administrator. This flaw leverages improper privilege management to grant unauthorized administrative control over the WordPress installation.
Business impact
Successful exploitation of this vulnerability results in full administrative control over the target WordPress site. This leads to complete data compromise, the potential for malicious code injection, and total loss of site integrity, justifying the critical CVSS score of 9.8.
Remediation
Immediate Action: Update the SEO Flow plugin to version 3.0.3 or later immediately to resolve the credential validation flaw.
Proactive Monitoring: Review web server access logs for suspicious API requests or unexpected administrative logins originating from unauthorized sources.
Compensating Controls: Deploy a Web Application Firewall with rules configured to block unauthorized access attempts to the specific API endpoints associated with the SEO Flow plugin.
Exploitation status
Public Exploit Available: No (no confirmed public exploit available in the provided data).
Analyst recommendation
Given the critical nature of this vulnerability and the potential for total site compromise, administrators must prioritize updating the SEO Flow plugin to version 3.0.3. Organizations should perform an audit of administrative user accounts following the update to ensure no unauthorized accounts were created during the exposure window.
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.8 (3.1)
- Analyst report written
- Published in the daily brief critical section, early-warning entry
Sources
Originally found and disclosed by Naoki Kawahigashi, with WPScan (coordinator), per the CVE Program record.