CVE-2026-78295

8.8

Xagio · Xagio SEO

A cross-site request forgery vulnerability in the Xagio SEO plugin allows unauthenticated attackers to perform unauthorized actions on behalf of users.

Executive summary

An unauthenticated cross-site request forgery vulnerability in Xagio SEO poses a high risk to WordPress installations by allowing unauthorized actions.

Vulnerability

This vulnerability is a cross-site request forgery (CWE-352) flaw that permits an unauthenticated attacker to trick a logged-in user into executing unintended actions through the browser. The attack requires no prior authentication and leverages the user's existing session to perform potentially privileged operations.

Business impact

The successful exploitation of this vulnerability could lead to unauthorized administrative actions, data modification, or configuration changes within the WordPress environment. Given the high CVSS score of 8.8, this flaw represents a significant risk to site integrity and security, potentially leading to total compromise of the affected application's settings.

Remediation

Immediate Action: Update the Xagio SEO plugin to version 7.1.0.44 or later immediately to resolve this security flaw.

Proactive Monitoring: Review application access logs for unusual patterns or unexpected administrative actions occurring without clear user initiation.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block suspicious cross-site request forgery attempts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing the Xagio SEO plugin must prioritize updating to the patched version 7.1.0.44 to prevent unauthorized manipulation of the site. Given the potential for total impact on the application, administrators should verify that the update is applied across all instances immediately to maintain a secure posture.

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Matheo Beuve | Patchstack Bug Bounty Program, per the CVE Program record.