THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-78362 — The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take ov

[NVD] CVE-2026-78362 — The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take ov

mednvdPublished 2026-09-05

CVE-2026-78362 CVSS: None Published: 2026-09-05T07:17:12.487

The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the SEO Flow by LupsOn

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-78362