Executive brief
Search Atlas SEO is a WordPress plugin used to optimize websites for search engines. A security flaw in versions 2.6.6 and earlier allows an attacker to trick a site administrator or visitor into executing malicious code by clicking a specially crafted link. This could lead to unauthorized actions being performed on the website, such as redirecting users to malicious sites or stealing sensitive session information.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Search Atlas SEO plugin for WordPress (versions <= 2.6.6) due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability is unauthenticated, meaning an attacker does not need an account on the target site, though it requires user interaction (such as a victim clicking a malicious link). Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions. The issue is resolved in version 2.6.7.
Affected products
- Search Atlas Group Search Atlas SEO <= 2.6.6
Timeline
- 2026-05-03: disclosed: Reported by Evan NR
- 2026-07-01: advisory: Patchstack advisory published
- 2026-07-02: patched: NVD publication and confirmation of fix in 2.6.7