Description
Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.
Published: 2026-07-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The SEOWP WordPress theme version 3.12.2 and older contain an unauthenticated Cross‑Site Request Forgery flaw that enables the injection of malicious script code into the site’s content. The injected code is persisted and executed on every page load that displays the compromised content, resulting in a stored XSS condition.

Affected Systems

WordPress sites that use the SEOWP theme from BlueAstralThemes, named SEOWP, with any version up to and including 3.12.2 are affected.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.1, indicating moderate to high severity, and has an EPSS score of less than 1%, signifying a very low but non‑zero likelihood of exploitation. It is not listed in the CISA KEV catalog. The attack vector is unauthenticated CSRF, meaning; based on the description it is inferred that the attacker would target a visitor who is already authenticated and has permission to modify content.

Generated by OpenCVE AI on July 21, 2026 at 11:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the SEOWP theme to the latest released version that addresses the CSRF flaw.
  • If an upgrade or uninstall the SEOWP theme to eliminate the vulnerable code.
  • Inspect the website’s stored content for injected scripts and remove any unauthorized or malicious code that may have been added.

Generated by OpenCVE AI on July 21, 2026 at 11:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Blueastralthemes
Blueastralthemes seowp
Wordpress
Wordpress wordpress
Vendors & Products Blueastralthemes
Blueastralthemes seowp
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.
Title WordPress SEOWP theme <= 3.12.2 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Blueastralthemes Seowp
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T15:52:36.393Z

Reserved: 2026-06-25T08:04:41.580Z

Link: CVE-2026-57761

cve-icon Vulnrichment

Updated: 2026-07-02T13:33:19.836Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:30:06Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)