PT-2026-5088 · WordPress · Wordpress+1
Kenneth Dunn
·
Published
2026-01-28
·
Updated
2026-01-28
·
CVE-2025-14386
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization versions 2.4.4 through 2.5.12
Description
The Search Atlas SEO plugin for WordPress has a flaw that allows authentication bypass. This occurs because of a missing capability check within the
generate sso url and validate sso token functions. Attackers with Subscriber-level access or higher can extract the nonce token authentication value and use it to log in as the first Administrator account.Recommendations
Versions 2.4.4 through 2.5.12 should be updated to a fixed version, if available. As a temporary workaround, restrict access to the
generate sso url and validate sso token functions.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Search Atlas Seo
Wordpress