Impact
The SEOWP WordPress theme version 3.12.2 and older contain an unauthenticated Cross‑Site Request Forgery flaw that enables the injection of malicious script code into the site’s content. The injected code is persisted and executed on every page load that displays the compromised content, resulting in a stored XSS condition.
Affected Systems
WordPress sites that use the SEOWP theme from BlueAstralThemes, named SEOWP, with any version up to and including 3.12.2 are affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating moderate to high severity, and has an EPSS score of less than 1%, signifying a very low but non‑zero likelihood of. It is not listed in the CISA KEV catalog. The attack vector is unauthenticated CSRF, meaning an attacker can trigger a request that injects malicious script into the site without authenticating themselves.
OpenCVE Enrichment