CVE-2025-15285Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The SEO Flow by LupsOnline plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the checkBlogAuthentication() and checkCategoryAuthentication() functions in all versions up to, and including, 2.2.1. These authorization functions only implement basic API key authentication but fail to implement WordPress capability checks. This makes it possible for unauthenticated attackers to create, modify, and delete blog posts and categories.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-04); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-04: 2Mentions · 2026-02-09: 1Technical Details · 2026-02-04: 1Technical Details · 2026-02-09: 102-0402-09
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-042
Disclosure1General1
2026-02-091
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2025-15285 The SEO Flow by LupsOnline plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the checkBlogAuthentication() … https://www.cve.org/CVERecord?id=CVE-2025-15285

    Post summary

    CVE‑2025‑15285 allows unauthorized data modification in the SEO Flow WordPress plugin because of a missing capability check.

    00010208
    56.5K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-15285 (CVSS:7.5, HIGH) is Awaiting Analysis. The SEO Flow by LupsOnline plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa..https://nvd.nist.gov/vuln/detail/CVE-2025-15285 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A new CVE (2025-15285) affecting the SEO Flow WordPress plugin has been reported with a high CVSS score and awaits analysis, but no exploit or patch details are provided.

    0000037
    171 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-15285 SEO Flow WordPress Plugin Unauthorized Data Modification via Authentication Bypass https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-15285

    Post summary

    A newly identified CVE (CVE-2025-15285) for the SEO Flow WordPress plugin allows unauthorized data modification by bypassing authentication, as reported on Vulmon.

    0000071
    4.0K followersView on X

Explore more