CVE-2026-78362
Received Received - Intake

Authentication Bypass in SEO Flow WordPress Plugin

Vulnerability report for CVE-2026-78362, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-05

Last updated on: 2026-09-05

Assigner: WPScan

Description

The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the SEO Flow by LupsOnline WordPress plugin before 3.0.3 to have been configured, which is its normal operating state.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-05
Last Modified
2026-09-05
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
lupsonline seo_flow to 3.0.2 (inc)
lupsonline seo_flow 3.0.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated privilege escalation flaw in the SEO Flow by LupsOnline WordPress plugin versions before 3.0.3. It allows unauthenticated users to impersonate the administrator who configured the plugin by exploiting improper credential validation in API requests. This can lead to full site takeover if the plugin is configured, which is its normal state.

Detection Guidance

Check if the SEO Flow by LupsOnline WordPress plugin is installed and its version is between 3.0.0 and 3.0.2. Inspect WordPress site logs for unauthorized API requests or unusual administrator activity. Use WP-CLI commands like 'wp plugin list' to verify plugin versions.

Impact Analysis

This vulnerability allows attackers to gain full administrative control of a WordPress site running the vulnerable plugin version. They can modify site content, install malicious plugins, steal data, or perform other unauthorized actions without needing valid credentials.

Compliance Impact

This vulnerability allows unauthenticated users to gain administrator-level access to a WordPress site by exploiting improper credential validation in the SEO Flow by LupsOnline plugin. Such unauthorized access could lead to data breaches, unauthorized data modification, or deletion, which are critical violations under GDPR and HIPAA. Compliance with these regulations requires strict access controls and protection of personal or sensitive health data, which this vulnerability directly undermines.

Mitigation Strategies

Update the SEO Flow by LupsOnline plugin to version 3.0.3 or later immediately. Disable the plugin temporarily if an update is not immediately available. Review user accounts for unauthorized administrator access and revoke any suspicious credentials.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78362. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart