CVE-2026-15946: Search Atlas SEO <= 2.6.23 - Missing Authorization to Authenticated (Subscriber+) Whitelabel Password Modification via handle_whitelabel_password_early Function
The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.23. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the whitelabel settings password to an attacker-controlled value, enabling them to unlock whitelabel-protected admin settings tabs including whitelabel, general, and advanced configuration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization (WordPress)to a version that resolves this vulnerability.Fixed in 2.6.23 - Compensating control
Restrict access to whitelabel-protected admin settings tabs (whitelabel, general, advanced configuration) to authorized roles only (e.g., disable/limit subscriber-level access if possible) until the plugin is updated.
Event History
Frequently Asked Questions
Which users can exploit this issue?
Any authenticated WordPress user with subscriber-level access or higher can exploit it. No administrator privileges or user interaction are required.
What can an attacker change or access?
An attacker can replace the whitelabel settings password with a value they control. They can then unlock whitelabel-protected administrative settings tabs, including whitelabel, general, and advanced configuration.
Which plugin versions are affected?
All Search Atlas SEO versions up to and including 2.6.23 are affected.