Executive brief
The Search Atlas SEO WordPress plugin allows low-privilege users to change the whitelabel admin password to their own value, bypassing access controls on sensitive configuration screens. An attacker with a subscriber account can unlock protected admin settings for whitelabel, general, and advanced configuration, potentially exposing site management controls.
Technical details
The plugin fails to properly verify user authorization before allowing modification of whitelabel settings password. An authenticated attacker with subscriber-level or higher privileges can overwrite the whitelabel password via an unprotected admin action, gaining unauthorized access to restricted configuration tabs. The vulnerability affects all versions up to and including 2.6.23.
Affected products
- Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization up to and including 2.6.23
Timeline
- 2026-09-19: disclosed