CVEFinder.io

CVE-2026-78362

⛔ critical
🔍 Scan for this CVE
Summary

The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the SEO Flow by LupsOnline WordPress plugin before 3.0.3 to have been configured, which is its normal operating state.

CVSS Score
9.8
Critical
EPSS Score
0.2
Exploit Probability
Published Date
2026-09-05
First Seen: 2026-09-06
📊 Relative Risk Intelligence

This CVE is Very High Risk - more severe than 90.5% of all 353,175 vulnerabilities in our database.

#33,631
Top 10% most severe
Severity Percentile
🎯 CISA SSVC Assessment Updated: Sep 6, 2026
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
YES
Can be exploited automatically
💥 Technical Impact
Total
Complete system compromise possible
🏆 Discovered By
Naoki Kawahigashi WPScan (coordinator)
SSVC data provided by CISA
Last Modified 2026-09-06
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE IDs (Weakness Types)

📦 Affected Products 0

No affected products information available

🔗 References 1