---
id: CVE-2026-78362
title: >-
  The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly
  validate the credential supplied with its API requests, allowing
  unauthenticated users to be served as the administrator who configured the SEO
  Flow by LupsOnlin…
summary: >-
  The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly
  validate the credential supplied with its API requests, allowing
  unauthenticated users to be served as the administrator who configured the SEO
  Flow by LupsOnlin…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
published: '2026-09-05'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:09:21.310'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78362'
references:
  - url: 'https://wpscan.com/vulnerability/0833424b-1231-4a48-be90-13fe4edc60c9/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00498
epssPercentile: 0.40055
ingestedAt: '2026-09-06T03:49:19.980Z'
---

## Overview

The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the SEO Flow by LupsOnline WordPress plugin before 3.0.3 to have been configured, which is its normal operating state.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
