Description
Cross-Site Request Forgery (CSRF) vulnerability in properfraction CrawlWP SEO allows Cross Site Request Forgery.

This issue affects CrawlWP SEO: from n/a through 3.0.16.
Published: 2026-07-05
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A CSRF flaw in the properfraction CrawlWP SEO plugin exists in all releases up to and including version 3.0.16. The vulnerability permits a malicious actor to persuade an authenticated user—or the site itself—to send an unintended request to the plugin’s endpoints, potentially allowing the attacker to perform privileged actions such as modifying content or changing plugin configuration. The weakness resides in a lack of proper request validation and is identified as CWE‑352.

Affected Systems

Any WordPress site that has installed the properfraction CrawlWP SEO plugin up to version 3.0.16 is affected. The issue applies to all installations that use this plugin, regardless of the site’s size or user base.

Risk and Exploitability

The CVSS base score of 4.3 indicates moderate severity, while the EPSS score of less than 1 % shows a low but non‑zero likelihood of exploitation at present. The vulnerability is not included in the CISA KEV catalog. Though the CVE description does not explicitly state the exact attack vector, it is inferred that the flaw can be exploited by sending a crafted HTTP request to the plugin’s endpoints while an administrator’s session is active, a typical CSRF attack path.

Generated by OpenCVE AI on July 23, 2026 at 15:37 UTC.

Remediation

Vendor Solution

Update the WordPress Index Now Plugin to the latest available version (at least 3.0.17).


OpenCVE Recommended Actions

  • Update the WordPress Index Now Plugin to the latest available version (at least 3.0.17).
  • If an upgrade is not immediately possible, disable or remove the plugin from the WordPress installation.
  • Apply a web application firewall or other security controls that block suspicious CSRF requests targeting the plugin’s endpoints.

Generated by OpenCVE AI on July 23, 2026 at 15:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Properfraction
Properfraction crawlwp Seo
Wordpress
Wordpress wordpress
Vendors & Products Properfraction
Properfraction crawlwp Seo
Wordpress
Wordpress wordpress

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 05 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in properfraction CrawlWP SEO allows Cross Site Request Forgery. This issue affects CrawlWP SEO: from n/a through 3.0.16.
Title WordPress CrawlWP SEO plugin <= 3.0.16 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Properfraction Crawlwp Seo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-06T15:14:38.329Z

Reserved: 2026-07-05T21:27:29.081Z

Link: CVE-2026-59520

cve-icon Vulnrichment

Updated: 2026-07-06T15:14:34.207Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T15:45:02Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)