CRITICAL 9.8 CVE-2026-78362 Published 5 Sept 2026

WordPress SEO Flow Plugin Admin Takeover

Worried this affects one of your servers?

The SEO Flow by LupsOnline WordPress plugin before 3.0.3 has a critical security vulnerability.

Unauthenticated users can exploit this issue to impersonate the administrator who configured the plugin and take over the site.

This vulnerability exists because the plugin does not validate the credentials supplied with its API requests.

All versions of the SEO Flow by LupsOnline WordPress plugin before 3.0.3 are affected.

Reference: CVE-2026-78362 on NVD

← Back to Security News