Executive brief
Xagio SEO is a WordPress plugin that helps optimize website content for search engines. The plugin contains a cross-site request forgery (CSRF) vulnerability that allows attackers to trick logged-in administrators into performing unintended actions—such as changing settings, deleting content, or modifying security configurations—without their knowledge or consent. Although the vulnerability requires user interaction, it could lead to unauthorized modifications of site settings or data loss.
Technical details
The vulnerability is an unauthenticated cross-site request forgery (CSRF) flaw in the Xagio SEO WordPress plugin affecting versions 7.1.0.43 and earlier. CSRF attacks exploit the trust relationship between a user's browser and a web application by embedding malicious requests in attacker-controlled pages; when a logged-in administrator visits such a page, the request is executed in their authenticated context. While the initial request can be triggered by an unauthenticated attacker (via a malicious link or webpage), successful exploitation requires a privileged user (authenticated WordPress administrator) to click the link or visit the crafted page. An attacker can manipulate plugin settings or perform administrative actions without the victim's knowledge. The vulnerability is patched in version 7.1.0.44 and later; administrators should update immediately.
Affected products
- Xagio SEO 7.1.0.43 and earlier
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Version 7.1.0.44 or later