Description
Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.
Published: 2026-07-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The SEOWP WordPress theme version 3.12.2 and older contain an unauthenticated Cross‑Site Request Forgery flaw that enables the injection of malicious script code into the site’s content. The injected code is persisted and executed on every page load that displays the compromised content, resulting in a stored XSS condition.

Affected Systems

WordPress sites that use the SEOWP theme from BlueAstralThemes, named SEOWP, with any version up to and including 3.12.2 are affected.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.1, indicating moderate to high severity, and has an EPSS score of less than 1%, signifying a very low but non‑zero likelihood of. It is not listed in the CISA KEV catalog. The attack vector is unauthenticated CSRF, meaning an attacker can trigger a request that injects malicious script into the site without authenticating themselves.

Generated by OpenCVE AI on August 3, 2026 at 05:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the SEOWP theme to the latest released version that addresses the CSRF flaw.
  • If an upgrade or uninstall the SEOWP theme to eliminate the vulnerable code.
  • Inspect the website’s stored content for injected scripts and remove any unauthorized or malicious code that may have been added.

Generated by OpenCVE AI on August 3, 2026 at 05:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Blueastralthemes
Blueastralthemes seowp
Wordpress
Wordpress wordpress
Vendors & Products Blueastralthemes
Blueastralthemes seowp
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.
Title WordPress SEOWP theme <= 3.12.2 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Blueastralthemes Seowp
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T15:52:36.393Z

Reserved: 2026-06-25T08:04:41.580Z

Link: CVE-2026-57761

cve-icon Vulnrichment

Updated: 2026-07-02T13:33:19.836Z

cve-icon NVD

Status : Deferred

Published: 2026-07-02T12:17:42.170

Modified: 2026-07-02T16:16:35.190

Link: CVE-2026-57761

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T05:45:03Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)