PT-2026-5088 · WordPress · Wordpress+1
Kenneth Dunn
·
Publicado
2026-01-28
·
Atualizado
2026-01-28
·
CVE-2025-14386
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization versions 2.4.4 through 2.5.12
Description
The Search Atlas SEO plugin for WordPress has a flaw that allows authentication bypass. This occurs because of a missing capability check within the
generate sso url and validate sso token functions. Attackers with Subscriber-level access or higher can extract the nonce token authentication value and use it to log in as the first Administrator account.Recommendations
Versions 2.4.4 through 2.5.12 should be updated to a fixed version, if available. As a temporary workaround, restrict access to the
generate sso url and validate sso token functions.Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Search Atlas Seo
Wordpress