PT-2026-5885 · WordPress · Seo Flow

Published

2026-02-04

·

Updated

2026-02-09

·

CVE-2025-15285

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions SEO Flow versions prior to 2.2.2
Description The SEO Flow plugin for WordPress is susceptible to unauthorized data modification because of a missing capability check within the checkBlogAuthentication() and checkCategoryAuthentication() functions. These functions rely solely on API key authentication without enforcing WordPress capability checks, allowing unauthenticated attackers to create, modify, and delete blog posts and categories.
Recommendations Update the SEO Flow plugin to version 2.2.2 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-15285

Affected Products

Seo Flow