Junglewise Threat Intelligence

CVE-2026-57761: BlueAstralThemes SEOWP CSRF to Stored XSS

CVE-2026-57761 · Severity: high · CVSS 7.1 · Published 2026-07-02

Executive brief

The SEOWP theme for WordPress is vulnerable to a security flaw that could allow an attacker to trick an administrator into performing unintended actions. By persuading a logged-in user to click a malicious link, an attacker could potentially change site settings or inject malicious scripts. This could lead to unauthorized changes to the website or the theft of sensitive information from visitors.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the SEOWP theme for WordPress (versions <= 3.12.2) due to insufficient validation of request origins. An unauthenticated remote attacker can exploit this by crafting a malicious request and tricking a logged-in administrator or high-privileged user into executing it via social engineering (e.g., clicking a link). Successful exploitation can lead to Stored Cross-Site Scripting (XSS), allowing the attacker to execute arbitrary scripts in the context of the victim's session. As of the advisory date, no official patch has been released.

Affected products

  • BlueAstralThemes SEOWP <= 3.12.2

Timeline

  • 2026-05-13: disclosed: Reported by adhikara13
  • 2026-07-02: advisory: Published by Patchstack and NVD

References