{"id":"CVE-2026-78295","published":"2026-09-17T14:17:30.303","lastModified":"2026-09-17T21:12:30.593","description":"Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-352"],"vendors":[],"products":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/xagio-seo/vulnerability/wordpress-xagio-seo-plugin-7-1-0-43-cross-site-request-forgery-csrf-vulnerability?_s_id=cve","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is an unauthenticated Cross Site Request Forgery (CSRF) vulnerability in Xagio SEO versions 7.1.0.43 and earlier, allowing attackers to perform unauthorized actions on behalf of authenticated users without their consent.","exploitability":"Exploitation is relatively straightforward as it requires the attacker to trick an authenticated user into performing actions on the affected Xagio SEO instance without their knowledge.","blast_radius":"If exploited, this vulnerability could result in unauthorized changes to the website's content or configuration, potentially leading to data loss or compromise of user information.","remediation":"Upgrade to Xagio SEO version 7.1.0.44 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["csrf","web","auth-bypass"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:09:59.101Z"}}