Impact
The CVE-2026-78295 vulnerability is an unauthenticated Cross Site Request Forgery flaw in Xagio SEO plugin versions up to 7.1.0.43. It allows an attacker to submit requests that the plugin treats as legitimate, enabling unauthorized actions on the WordPress site. The core weakness is the lack of CSRF protection, classified under CWE‑352. Based on the description, it is inferred that an attacker could modify plugin settings, delete content, or inject malicious data, depending on which plugin functions are exposed through the CSRF path.
Affected Systems
WordPress sites that have the Xagio SEO plugin installed with any version 7.1.0.43 or earlier are vulnerable. This includes any site owner or administrator who has not upgraded past that version. Site owners should verify the plugin version via the WordPress plugin dashboard.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score is currently unavailable, so the probability of exploitation cannot be precisely quantified; however, the flaw remains a significant risk due to its unauthenticated nature and systematic attack pathway. The vulnerability is not listed in the CISA KEV catalog, implying no known large‑scale exploitation at the time of this report. The likely attack vector is an attacker hosting a malicious site that submits forged POST or GET requests to the vulnerable plugin endpoint, leveraging the victim's authenticated session to manipulate site content or settings. Based on the description, it is inferred that the attack would involve exploiting the lack of CSRF protection to perform unauthorized actions.
OpenCVE Enrichment