medium · CVSS v3 4.3 · EPSS 0.00232
CVE-2026-15946
The Search Atlas SEO plugin for WordPress has an authorization bypass that allows any authenticated user with subscriber-level access to cha
Overview
The Search Atlas SEO plugin for WordPress has an authorization bypass that allows any authenticated user with subscriber-level access to change the whitelabel settings password. This lets attackers unlock protected admin tabs such as whitelabel, general, and advanced configuration. The flaw exists in all versions up to 2.6.23.
Description
The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.23. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the whitelabel settings password to an attacker-controlled value, enabling them to unlock whitelabel-protected admin settings tabs including whitelabel, general, and advanced configuration.
Impact
Confidentiality: attackers can view and modify whitelabel settings. Integrity: they can change configuration. Availability: not directly affected. Defenders: site administrators and WordPress users with subscriber-level access.
Remediation
Update the plugin to version 2.6.24 or later. If update not possible, disable whitelabel features or restrict subscriber-level access. Monitor for unauthorized changes to plugin settings.
Risk context
The vulnerability has a medium severity score and a very low EPSS of 0.00232, indicating a low likelihood of exploitation in the wild, but defenders should still patch promptly to prevent potential privilege escalation.
Affected products
- Search Atlas SEO
- WordPress
- WP Publishing
- Integrated AI Optimization
Scores
- Severity
- medium
- CVSS v2
- 4
- CVSS v3
- 4.3
- CVSS v4
- —
- EPSS
- 0.00232