Cross Site Request Forgery Vulnerability in Xagio SEO Plugin by Xagio
CVE-2026-78295

8.8HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-78295?

The Xagio SEO plugin for WordPress contains a serious vulnerability that allows unauthenticated attackers to exploit Cross Site Request Forgery (CSRF) issues. This flaw can enable unauthorized actions on behalf of unsuspecting users, potentially compromising the integrity and security of the affected WordPress sites. Users are advised to update to the latest version and implement security measures to mitigate the risks associated with this vulnerability.

Affected Version(s)

Xagio SEO <= 7.1.0.43

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Matheo Beuve | Patchstack Bug Bounty Program
.