Impact
The Search Atlas SEO – OTTO AI SEO Automation plugin suffers from a missing authorization check, allowing authenticated users with subscriber-level privileges or higher to change the whitelabel password to a value of their choosing. This vulnerability enables the attacker to unlock otherwise protected administration tabs such as whitelabel, general, and advanced configuration, potentially altering site settings and undermining the intended security boundaries of the plugin.
Affected Systems
All installations of Search Atlas SEO – OTTO AI SEO Automation for WordPress up to and including version 2.6.23 are affected. Users on earlier releases of the plugin are also impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated account with subscriber-level access or higher; the attacker must be logged in to the WordPress site to supply the new password value. No remote execution or privilege escalation beyond the authorized user role is provided by this flaw.
OpenCVE Enrichment