Impact
A CSRF flaw exists in all versions of the properfraction CrawlWP SEO plugin up to 3.0.16. The vulnerability means that a malicious actor can cause a logged‑in user—or the site itself—to send an unintended request to the plugin’s endpoints, allowing the attacker to execute actions that the authenticated user is permitted to perform. The weakness is identified as CWE‑352.
Affected Systems
WordPress installations that have the properfraction CrawlWP SEO plugin at any version through 3.0.16 are impacted. The plugin can be installed on any WordPress site regardless of size or user base.
Risk and Exploitability
The CVSS base score of 4.3 indicates moderate impact. The EPSS score of <1% suggests a low but still present exploitation probability. The vulnerability is not cataloged in the CISA KEV. Although the description does not specify a precise attack vector, it is reasonable to infer that exploitation would occur through the plugin’s HTTP endpoints while an authenticated session is active, following typical CSRF patterns.
OpenCVE Enrichment