Cross-Site Request Forgery Vulnerability in Seo Monster Plugin for WordPress
CVE-2025-9620
6.1MEDIUM
What is CVE-2025-9620?
The Seo Monster plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF) due to inadequate nonce validation in its check_integration() function. This flaw allows unauthenticated attackers to manipulate plugin settings by deceiving a site administrator into executing a malicious action, possibly by clicking on a crafted link. Such exploitation could lead to the injection of harmful web scripts, compromising the integrity of the website.
Affected Version(s)
Seo Monster * <= 3.3.3