---
id: CVE-2026-15946
title: >-
  The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing &
  Integrated AI Optimization plugin for WordPress is vulnerable to authorization
  bypass in all versions up to, and including, 2.6.23
summary: >-
  The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing &
  Integrated AI Optimization plugin for WordPress is vulnerable to authorization
  bypass in all versions up to, and including, 2.6.23. This is due to the plugin
  not pro…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
vendor: shahrukhlinkgraph
product: Search Atlas SEO – OTTO AI SEO Automation for WordPress
affected:
  - search_atlas_seo_otto_ai_seo_automation_for_wordpress <= 2.6.23
published: '2026-09-19'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T13:33:33.387'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15946'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/metasync/tags/2.6.16/admin/class-metasync-admin.php#L215
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/metasync/tags/2.6.16/includes/class-metasync-connect-manager.php#L1049
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/metasync/tags/2.6.16/includes/class-metasync-settings-registration.php#L96
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/metasync/tags/2.6.17/admin/class-metasync-admin.php#L215
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/metasync/tags/2.6.17/includes/class-metasync-connect-manager.php#L1049
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/metasync/tags/2.6.17/includes/class-metasync-settings-registration.php#L96
    label: security@wordfence.com
  - url: 'https://plugins.trac.wordpress.org/changeset/3676919'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/56d839b0-b29d-4299-af77-1ce97a5925f6?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
epss: 0.00232
epssPercentile: 0.12529
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-19T13:23:48.641031Z'
ingestedAt: '2026-09-19T07:59:56.109Z'
---

## Overview

The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.23. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the whitelabel settings password to an attacker-controlled value, enabling them to unlock whitelabel-protected admin settings tabs including whitelabel, general, and advanced configuration.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
