CVE-2026-78295
8.8Xagio · Xagio SEO
A cross-site request forgery vulnerability in the Xagio SEO plugin allows unauthenticated attackers to perform unauthorized actions on behalf of users.
Executive summary
An unauthenticated cross-site request forgery vulnerability in Xagio SEO poses a high risk to WordPress installations by allowing unauthorized actions.
Vulnerability
This vulnerability is a cross-site request forgery (CWE-352) flaw that permits an unauthenticated attacker to trick a logged-in user into executing unintended actions through the browser. The attack requires no prior authentication and leverages the user's existing session to perform potentially privileged operations.
Business impact
The successful exploitation of this vulnerability could lead to unauthorized administrative actions, data modification, or configuration changes within the WordPress environment. Given the high CVSS score of 8.8, this flaw represents a significant risk to site integrity and security, potentially leading to total compromise of the affected application's settings.
Remediation
Immediate Action: Update the Xagio SEO plugin to version 7.1.0.44 or later immediately to resolve this security flaw.
Proactive Monitoring: Review application access logs for unusual patterns or unexpected administrative actions occurring without clear user initiation.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block suspicious cross-site request forgery attempts.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing the Xagio SEO plugin must prioritize updating to the patched version 7.1.0.44 to prevent unauthorized manipulation of the site. Given the potential for total impact on the application, administrators should verify that the update is applied across all instances immediately to maintain a secure posture.
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Matheo Beuve | Patchstack Bug Bounty Program, per the CVE Program record.