Impact
A CSRF flaw in the properfraction CrawlWP SEO plugin exists in all releases up to and including version 3.0.16. The vulnerability permits a malicious actor to persuade an authenticated user—or the site itself—to send an unintended request to the plugin’s endpoints, potentially allowing the attacker to perform privileged actions such as modifying content or changing plugin configuration. The weakness resides in a lack of proper request validation and is identified as CWE‑352.
Affected Systems
Any WordPress site that has installed the properfraction CrawlWP SEO plugin up to version 3.0.16 is affected. The issue applies to all installations that use this plugin, regardless of the site’s size or user base.
Risk and Exploitability
The CVSS base score of 4.3 indicates moderate severity, while the EPSS score of less than 1 % shows a low but non‑zero likelihood of exploitation at present. The vulnerability is not included in the CISA KEV catalog. Though the CVE description does not explicitly state the exact attack vector, it is inferred that the flaw can be exploited by sending a crafted HTTP request to the plugin’s endpoints while an administrator’s session is active, a typical CSRF attack path.
OpenCVE Enrichment