PT-2026-5885 · WordPress · Seo Flow
CVE-2025-15285
·
Publicado
2026-02-04
·
Atualizado
2026-02-09
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SEO Flow versions prior to 2.2.2
Description
The SEO Flow plugin for WordPress is susceptible to unauthorized data modification because of a missing capability check within the
checkBlogAuthentication() and checkCategoryAuthentication() functions. These functions rely solely on API key authentication without enforcing WordPress capability checks, allowing unauthenticated attackers to create, modify, and delete blog posts and categories.Recommendations
Update the SEO Flow plugin to version 2.2.2 or later.
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Seo Flow