Executive brief
The Sentence To SEO plugin for WordPress, which helps manage website metadata for search engine optimization, contains a security flaw that could allow an attacker to change plugin settings. By tricking a site administrator into clicking a malicious link, an attacker can bypass security checks to modify configurations or inject unauthorized scripts. This could lead to unauthorized changes to the website's SEO data or the execution of malicious code in the administrator's browser.
Technical details
The Sentence To SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the create_admin_page() function. This vulnerability affects all versions up to and including 1.0. An unauthenticated attacker can exploit this by tricking a logged-in administrator into interacting with a malicious link or crafted request. Successful exploitation allows the attacker to modify plugin settings and potentially perform Stored Cross-Site Scripting (XSS) by injecting malicious scripts into the site's configuration. The attack requires user interaction from a privileged user.
Affected products
- Sentence To SEO Sentence To SEO (keywords, description and tags) Up to, and including, 1.0
Timeline
- 2026-05-20: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/sentence-to-seo/tags/1.0/index.php
- https://plugins.trac.wordpress.org/browser/sentence-to-seo/tags/1.0/index.php
- https://plugins.trac.wordpress.org/browser/sentence-to-seo/tags/1.0/index.php
- https://plugins.trac.wordpress.org/browser/sentence-to-seo/tags/1.0/index.php
- https://plugins.trac.wordpress.org/browser/sentence-to-seo/trunk/index.php
- https://plugins.trac.wordpress.org/browser/sentence-to-seo/trunk/index.php
- https://plugins.trac.wordpress.org/browser/sentence-to-seo/trunk/index.php