Junglewise Threat Intelligence

CVE-2026-57430: SEOPress SEOPress PRO broken access control in Contributor role

CVE-2026-57430 · Severity: medium · CVSS 4.3 · Published 2026-06-26

Executive brief

SEOPress PRO, a premium WordPress plugin used for search engine optimization, contains a security flaw that allows users with low-level 'Contributor' accounts to perform actions they should not be authorized to do. While the impact is considered low, an attacker could potentially modify certain site settings or metadata, affecting how the site appears in search results. This issue is resolved by updating to version 9.2 or later.

Technical details

A broken access control vulnerability exists in SEOPress PRO versions up to and including 9.1.1 due to missing authorization checks (CWE-862). An authenticated attacker with Contributor-level privileges can exploit this flaw via network requests to execute functions or modify settings that should be restricted to higher-privileged users. The vulnerability is classified as having low integrity impact and no confidentiality or availability impact. A fix is available in version 9.2.

Affected products

  • SEOPress Free SEOPress PRO <= 9.1.1

Timeline

  • 2025-09-08: other: Reported by MD Shariful Islam
  • 2026-06-25: advisory: Published by Patchstack
  • 2026-06-26: disclosed: NVD Published Date

References