Impact
The vulnerability is a Cross‑Site Request Forgery flaw that allows a malicious actor to trick an authenticated user into performing privileged actions through the Seo Meta Tags plugin. Because the plugin processes administrative requests without adequate CSRF verification, an adversary can elevate privileges or change site settings, compromising confidentiality, integrity, and availability of the affected WordPress site.
Affected Systems
The plugin Purab Seo Meta Tags, current releases up to and including 1.4, is vulnerable. WordPress sites that have installed any version of this plugin through the specified upper bound are at risk.
Risk and Exploitability
With a CVSS score of 8.8 the issue is high severity and, despite an EPSS score below 1 percent, it could be exploited by attackers who have access to an authenticated session or can persuade a user to click a crafted link. The vulnerability is not listed in the CISA KEV catalog, but the cost of exploitation could be significant for sites that rely on the plugin for SEO management.
OpenCVE Enrichment
EUVD