Description
Cross-Site Request Forgery (CSRF) vulnerability in Allegro Marketing hpb seo plugin for WordPress hpbseo allows Reflected XSS.This issue affects hpb seo plugin for WordPress: from n/a through <= 3.0.1.
Published: 2025-10-29
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The hpb seo plugin for WordPress contains a Cross‑Site Request Forgery flaw that allows an attacker to trigger privileged actions using a victim’s authenticated session. The weakness (CWE‑352) arises from insufficient anti‑CSRF validation, and the reported issue also leads to reflected X‑SS scripting in certain circumstances. An attacker who can lure a logged‑in site administrator or other privileged user to visit a crafted URL could force the plugin to perform state‑changing operations such as modifying SEO settings or injecting malicious content, thereby compromising the integrity and confidentiality of the site’s data.

Affected Systems

This vulnerability affects the Allegro Marketing hpb seo plugin for WordPress, versions released up to and including 3.0.1. Any deployment of those releases on a WordPress installation is potentially exposed, regardless of the WordPress core version.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high severity, while the EPSS score of less than 1% suggests the likelihood of exploitation remains low at present. However, because CSRF attacks occur via normal web traffic, the vulnerability is exploitable by unauthenticated actors who prompt a victim to visit a malicious link, or by authenticated users lacking strict CSRF safeguards. Although the vulnerability is not listed in the CISA KEV catalog yet, the potential for data integrity loss and unauthorized changes warrants prompt attention.

Generated by OpenCVE AI on April 29, 2026 at 14:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest hpb seo plugin release that addresses the CSRF issue or apply any vendor‑provided patch.
  • If an immediate update is not possible, disable the plugin’s functionality or remove the plugin until a fix is available to eliminate the vulnerable endpoint.
  • Enable WordPress’s native CSRF protection for all state‑changing requests by configuring nonces or, if the plugin does not enforce them, add a temporary nonce check via custom code or a security plugin.

Generated by OpenCVE AI on April 29, 2026 at 14:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 30 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Allegro Marketing
Allegro Marketing hpb Seo Plugin For Wordpress
Wordpress
Wordpress wordpress
Vendors & Products Allegro Marketing
Allegro Marketing hpb Seo Plugin For Wordpress
Wordpress
Wordpress wordpress

Wed, 29 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Oct 2025 09:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Allegro Marketing hpb seo plugin for WordPress hpbseo allows Reflected XSS.This issue affects hpb seo plugin for WordPress: from n/a through <= 3.0.1.
Title WordPress hpb seo plugin for WordPress plugin <= 3.0.1 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References

Subscriptions

Allegro Marketing Hpb Seo Plugin For Wordpress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T18:36:35.534Z

Reserved: 2025-09-25T15:19:48.981Z

Link: CVE-2025-60075

cve-icon Vulnrichment

Updated: 2025-10-29T13:43:28.745Z

cve-icon NVD

Status : Deferred

Published: 2025-10-29T09:15:38.077

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-60075

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T14:15:14Z

Weaknesses