Xagio SEO - Privilege Escalation vulnerability
criticalPrivilege Escalation vulnerability
- CVSS:
- 9.8
- Affected:
- up to 7.1.0.30
- Fixed in:
- 7.1.0.31
- Disclosed:
- Mar 12, 2026
plugin
12 known security issues reported for the Xagio Seo WordPress plugin. Most recent disclosed Mar 12, 2026.
Running Xagio Seo on your site? Check whether your installed version is affected.
Scan your site freePrivilege Escalation vulnerability
The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.1.0.30. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
[en] The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.1.0.30 via the 'pixabayDownloadImage' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary loca...
The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.1.0.30 via the 'pixabayDownloadImage' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations...
[en] Missing Authorization vulnerability in Xagio SEO Xagio SEO xagio-seo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Xagio SEO: from n/a through <= 7.1.0.29.
The Xagio SEO plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.1.0.37. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
[en] The Xagio SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.1.0.5 via the backup functionality due to weak filename structure and lack of protection in the directory. This makes it possible for unauthenticated attackers to extract sensitive data from b...
The Xagio SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.1.0.5 via the backup functionality due to weak filename structure and lack of protection in the directory. This makes it possible for unauthenticated attackers to extract sensitive data from backup...
The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘HTTP_REFERER’ parameter in all versions up to, and including, 7.1.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...
The Xagio SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.0.0.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages tha...
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xagio Xagio SEO allows Stored XSS. This issue affects Xagio SEO: from n/a through 7.0.0.20.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free