CVE-2026-78362: SEO Flow by LupsOnline 3.0.0 - 3.0.2 - Unauthenticated Privilege Escalation via API Key Authentication

Published Sep 5, 2026
·
Updated

The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the SEO Flow by LupsOnline WordPress plugin before 3.0.3 to have been configured, which is its normal operating state.

Affected Software

1 affected component
LupsOnline SEO Flow by LupsOnline WordPress plugin<3.0.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SEO Flow by LupsOnline WordPress to a version that resolves this vulnerability.

    Fixed in 3.0.3
  2. Operational

    If the SEO Flow by LupsOnline WordPress plugin API key credentials were exposed by an unauthenticated attacker before upgrading to 3.0.3, rotate/revoke those credentials after upgrading.

Event History

Sep 5, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Which sites are realistically exposed to takeover?

Sites using SEO Flow by LupsOnline versions 3.0.0 through 3.0.2 are exposed when the plugin has been configured. Configuration is the plugin’s normal operating state, so deployed instances should be treated as potentially affected.

2

Does an attacker need an account or valid API credential?

No. The issue allows unauthenticated users to be treated as the administrator who configured the plugin because supplied API credentials are not correctly validated.

3

What is the immediate remediation?

Update the plugin to version 3.0.3 or later. The affected versions are those before 3.0.3.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203