Description
Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Request Forgery
Action: Patch Now
AI Analysis

Impact

The CVE-2026-78295 vulnerability is an unauthenticated Cross Site Request Forgery flaw in Xagio SEO plugin versions up to 7.1.0.43. It allows an attacker to submit requests that the plugin treats as legitimate, enabling unauthorized actions on the WordPress site. The core weakness is the lack of CSRF protection, classified under CWE‑352. Based on the description, it is inferred that an attacker could modify plugin settings, delete content, or inject malicious data, depending on which plugin functions are exposed through the CSRF path.

Affected Systems

WordPress sites that have the Xagio SEO plugin installed with any version 7.1.0.43 or earlier are vulnerable. This includes any site owner or administrator who has not upgraded past that version. Site owners should verify the plugin version via the WordPress plugin dashboard.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity. The EPSS score is currently unavailable, so the probability of exploitation cannot be precisely quantified; however, the flaw remains a significant risk due to its unauthenticated nature and systematic attack pathway. The vulnerability is not listed in the CISA KEV catalog, implying no known large‑scale exploitation at the time of this report. The likely attack vector is an attacker hosting a malicious site that submits forged POST or GET requests to the vulnerable plugin endpoint, leveraging the victim's authenticated session to manipulate site content or settings. Based on the description, it is inferred that the attack would involve exploiting the lack of CSRF protection to perform unauthorized actions.

Generated by OpenCVE AI on September 17, 2026 at 21:19 UTC.

Remediation

Vendor Solution

Update the WordPress Xagio SEO Plugin to the latest available version (at least 7.1.0.44).


OpenCVE Recommended Actions

  • Update the Xagio SEO Plugin to 7.1.0.44 or later to eliminate the CSRF deficiency.
  • If an update cannot be applied immediately, temporarily deactivate the plugin to remove the attack surface until patching is possible.
  • Inspect any other plugins or custom code on the site for similar functionality that may lack CSRF safeguards, and upgrade or remove them as necessary.

Generated by OpenCVE AI on September 17, 2026 at 21:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Xagio
Xagio xagio Seo
Vendors & Products Wordpress
Wordpress wordpress
Xagio
Xagio xagio Seo

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.
Title WordPress Xagio SEO plugin <= 7.1.0.43 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Wordpress Wordpress
Xagio Xagio Seo
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-17T14:07:07.641Z

Reserved: 2026-08-24T07:38:18.806Z

Link: CVE-2026-78295

cve-icon Vulnrichment

Updated: 2026-09-17T14:07:03.974Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:30.303

Modified: 2026-09-17T21:12:30.593

Link: CVE-2026-78295

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:30:18Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)