rootpwn

medium · CVSS v3 4.3 · EPSS 0.00232

CVE-2026-15946

The Search Atlas SEO plugin for WordPress has an authorization bypass that allows any authenticated user with subscriber-level access to cha

Overview

The Search Atlas SEO plugin for WordPress has an authorization bypass that allows any authenticated user with subscriber-level access to change the whitelabel settings password. This lets attackers unlock protected admin tabs such as whitelabel, general, and advanced configuration. The flaw exists in all versions up to 2.6.23.

Description

The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.23. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the whitelabel settings password to an attacker-controlled value, enabling them to unlock whitelabel-protected admin settings tabs including whitelabel, general, and advanced configuration.

Impact

Confidentiality: attackers can view and modify whitelabel settings. Integrity: they can change configuration. Availability: not directly affected. Defenders: site administrators and WordPress users with subscriber-level access.

Remediation

Update the plugin to version 2.6.24 or later. If update not possible, disable whitelabel features or restrict subscriber-level access. Monitor for unauthorized changes to plugin settings.

Risk context

The vulnerability has a medium severity score and a very low EPSS of 0.00232, indicating a low likelihood of exploitation in the wild, but defenders should still patch promptly to prevent potential privilege escalation.

Affected products

  • Search Atlas SEO
  • WordPress
  • WP Publishing
  • Integrated AI Optimization

Scores

Severity
medium
CVSS v2
4
CVSS v3
4.3
CVSS v4
EPSS
0.00232

authorization-bypass wordpress-plugin whitelabel subscriber-access configuration-change moderate-severity low-epss

← All CVEs