PT-2026-5885 · WordPress · Seo Flow
Published
2026-02-04
·
Updated
2026-02-09
·
CVE-2025-15285
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SEO Flow versions prior to 2.2.2
Description
The SEO Flow plugin for WordPress is susceptible to unauthorized data modification because of a missing capability check within the
checkBlogAuthentication() and checkCategoryAuthentication() functions. These functions rely solely on API key authentication without enforcing WordPress capability checks, allowing unauthenticated attackers to create, modify, and delete blog posts and categories.Recommendations
Update the SEO Flow plugin to version 2.2.2 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Seo Flow