CVE-2025-3302
Published
CVSS v3
7.2
HIGH
CVSS v2
N/A
Affected
1
PROJECT
Description
The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘HTTP_REFERER’ parameter in all versions up to, and including, 7.1.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 7.1.0.0.
<h3>Xagio SEO takes an entirely new approach to SEO by combining keyword & competition research, clustering & optimization, content & schema and all of it is powered by AI!</h3>
<p>Forget endless checklists and manual optimizations – <strong>Xagio AI handles it for you</strong> while the <strong>Project Planner centralizes your entire SEO workflow</strong>.</p>
<p><strong>✅AI-Powered SEO</strong><br />
Instantly generate <strong>WordPress SEO titles, meta descriptions, content, and schema</strong> with AI.</p>
<p><strong>✅Project Planner</strong><br />
Optimize your entire website <strong>from a single dashboard</strong> instead of jumping between tools.</p>
<p><strong>✅Built-in Features</strong><br />
Everything you need for WordPress SEO <strong>without requiring extra plugins or upgrades</strong>.</p>
<p><strong>✅Xagio includes AI-powered optimizations at no cost – no hidden paywalls, just smarter SEO.</strong></p>
<p>With <strong>AI-driven automation</strong> and <strong>a structured workflow</strong>, Xagio makes <strong>powerful SEO simple, fast, and effective.</strong></p>
<span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/W95Ka2Y8nws?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span>
<h3>🎯 Is Xagio the Right WordPress SEO Plugin for You?</h3>
<p>Xagio is built for <strong>everyone</strong>, from solo website owners to large agencies managing multiple clients.</p>
<p><strong>✅ For Beginners</strong><br />
No experience? No problem. Xagio AI automates keyword research, meta optimization, and schema generation – so you get <strong>fast SEO results without the learning curve</strong>.</p>
<p><strong>💼 For Business Owners</strong><br />
Rank higher and drive traffic <strong>without hiring an SEO expert</strong>. Xagio <strong>handles technical SEO</strong> while you focus on growing your business.</p>
<p><strong>⚡ For SEO Professionals & Agencies</strong><br />
Xagio <strong>automates, centralizes, and optimizes</strong> your workflow, from <strong>sales & onboarding to fulfillment & reporting</strong>. Replace multiple tools, reduce inefficiencies, and <strong>maximize client retention and profitability</strong>.</p>
<p><strong>🔗 For Affiliates</strong><br />
Optimize niche sites, product reviews, and landing pages with <strong>AI-powered SEO</strong> – increase rankings and <strong>earn more commissions with less effort</strong>.</p>
<p><strong>🏗️ For PBN Managers</strong><br />
Xagio <strong>Network Management tools</strong> simplify the process of maintaining <strong>large private blog networks</strong>, helping you <strong>organize, update, and optimize multiple sites in one place</strong>.</p>
<p><strong>📍For Local SEO Experts</strong><br />
Dominate local rankings with <strong>AI-optimized metadata, schema, and structured content</strong> – boosting visibility for <strong>Google Maps and local searches</strong>.</p>
<p><strong>🛒 For eCommerce Stores</strong><br />
Enhance <strong>product pages, categories, and descriptions</strong> with AI-driven SEO – <strong>improve rankings, click-through rates, and sales</strong> effortlessly.</p>
<h3><strong>The Project Planner – Optimize & Edit Your Entire Site from One Dashboard</strong></h3>
<p><em>“The most valuable asset any SEO has is time, and with Xagio Project Planner, you’ll get it back.â€</em></p>
<p>The <strong>Project Planner is the command center for your SEO strategy</strong>. Instead of switching between tools, Xagio <strong>organizes all SEO data by page</strong> – including keywords, rankings, competition, and CPC – so you can <strong>optimize faster and make smarter decisions</strong>.</p>
<p><strong>✅ AI-Powered Bulk Optimization</strong><br />
Apply <strong>AI-generated titles, meta descriptions, and H1s</strong> across multiple pages at once – saving hours of manual work.</p>
<p><strong>✅ Instant Site & Keyword Onboarding</strong><br />
<strong>Import all pages, keywords, and rankings in one step</strong>, streamlining optimization.</p>
<p><strong>✅ Full-Site SEO, Organized by Page</strong><br />
View <strong>keywords, rankings, competition, CPC – grouped per page</strong> for <strong>faster, smarter optimization workflows</strong>.</p>
<p><strong>✅ Bring Your Own Data</strong><br />
Already have keyword research? <strong>Import your keyword list instantly</strong> and let Xagio’s AI handle the rest.</p>
<p><strong>✅ Advanced Keyword Clustering</strong><br />
Group <strong>thousands of keywords</strong> into <strong>highly relevant, structured groups</strong> – helping you create <strong>better-targeted content</strong>.</p>
<p><strong>✅ Seeding for Precision Targeting</strong><br />
Search for <strong>specific words or patterns</strong> across all keyword groups and <strong>pull them into a single focused group</strong> for precise content planning.</p>
<p><strong>✅ With Xagio AI-driven workflows</strong>, you can <strong>optimize entire websites faster, eliminate guesswork, and make data-driven SEO decisions – all from one dashboard</strong>. 🚀</p>
<h3>🔥 Everything You Need for SEO – Completely Integrated</h3>
<p>Xagio combines <strong>AI-powered SEO</strong> with essential site management tools, so you can <strong>rank higher without expensive add-ons</strong>.</p>
<span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/Hwnn9WovaKQ?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span>
<h3>🚀 AI-Powered SEO Optimization</h3>
<ul>
<li><strong>AI Meta Optimization</strong> – Instantly generate SEO-friendly titles, descriptions, and headers.</li>
<li><strong>AI Content</strong> – Create structured, search-optimized content in a single click.</li>
<li><strong>AI Schema</strong> – Automatically generate structured data for rich snippets & better SERP visibility.</li>
</ul>
<h3>📊 Project Planning & Keyword Management</h3>
<ul>
<li><strong>The Project Planner</strong> – Manage & optimize your entire site from one dashboard.</li>
<li><strong>Keyword Import & Clustering</strong> – Organize keywords into strategic groups for better content planning.</li>
<li><strong>Seeding for Precision Targeting</strong> – Pull specific keywords from multiple groups into a single focus group.</li>
<li><strong>Automatic Site Audit (Ranking Keywords Per Page)</strong> – Instantly discover which keywords your pages rank for.</li>
</ul>
<h3>⚙️ On-Page SEO</h3>
<ul>
<li><strong>Edit H1, Title, and Meta Descriptions in the page editor</strong> – Optimize directly while creating content.</li>
<li><strong>Centralized H1, Title, and Meta Description management</strong> – Edit and update in one place for better efficiency.</li>
</ul>
<h3>🔀 301 & 404 Management</h3>
<ul>
<li><strong>Create unlimited 301 redirects</strong> – Redirect old URLs to maintain SEO value.</li>
<li><strong>404 monitoring for high-traffic pages</strong> – Identify and fix broken links before they hurt your rankings.</li>
</ul>
<h3>🏗️ Content Silo Management</h3>
<ul>
<li><strong>Physical Silos via Pages</strong> – Strengthen SEO by structuring content hierarchically.</li>
<li><strong>Virtual Silos via Links</strong> – Improve internal linking without changing your site structure.</li>
<li><strong>Organize Blogs with Tags & Categories</strong> – Keep content structured for better discoverability.</li>
</ul>
<h3>🔗 Link Management</h3>
<ul>
<li><strong>Track Image & Text Links</strong> – Monitor performance and engagement.</li>
<li><strong>Link Impressions, Clicks & Conversion Stats</strong> – Gain insights into link performance.</li>
<li><strong>Use Shortcodes for Internal Links</strong> – Simplify internal linking across your site.</li>
<li><strong>Masked Links for External Use</strong> – Keep external URLs clean and trackable.</li>
</ul>
<h3>⭐ Customer Reviews</h3>
<ul>
<li><strong>Fully Customizable Review Design & Fields</strong> – Collect and display reviews the way you want.</li>
<li><strong>Collect Reviews, Ratings, or Both</strong> – Build trust and credibility with user-generated content.</li>
<li><strong>Global or Per Page Review Functionality</strong> – Control where and how reviews appear.</li>
<li><strong>Automatic Aggregate Rating Calculation & Schema Injection</strong> – Boost SEO with structured review data.</li>
</ul>
<h3>💾 Fully Automated Backup & Restore</h3>
<ul>
<li><strong>Save Backups Locally or to Cloud</strong> – Keep your data secure.</li>
<li><strong>Set Up Automated Backup Schedules</strong> – Never lose important site information.</li>
<li><strong>1-Click Restore from Backups</strong> – Recover lost data instantly.</li>
</ul>
<h3>🔁 WordPress Cloning</h3>
<ul>
<li><strong>Clone WordPress Site from URL</strong> – Quickly duplicate entire sites.</li>
<li><strong>Backup Source & Target Domains Before Cloning</strong> – Ensure safe migrations.</li>
</ul>
<h3>🛠️ Rescue Center</h3>
<ul>
<li><strong>Easy & Advanced Restore Modes</strong> – Roll back changes effortlessly.</li>
<li><strong>Fix Broken Plugins & Themes</strong> – Repair corrupted installations.</li>
<li><strong>Scan Media Library for Malware</strong> – Protect your site from security threats.</li>
</ul>
<h3>SEO Has Evolved – It’s Time to Evolve With It 🚀</h3>
<p>Traditional SEO is <strong>slow, expensive, and frustrating</strong>.</p>
<p>Xagio AI <strong>eliminates complexity</strong>, giving you the <strong>fastest, easiest way to rank higher and drive more traffic</strong>.</p>
<p><strong>Stop wasting time with outdated methods – install Xagio today and start ranking smarter.</strong> 🚀</p>
<h3>Third-Party Services</h3>
<p>This plugin relies on third-party services to provide certain functionalities. Below is a list of the services used and the purposes for which they are used.</p>
<h3>Xagio Panel API</h3>
<ul>
<li><em>Purpose:</em> This service is used for license verification, updates, and website management, ensuring the plugin operates smoothly and stays up-to-date with the latest features and security patches.</li>
<li><em>Service URL:</em> <a href="https://app.xagio.net" rel="nofollow ugc">Xagio Panel</a></li>
<li><em>Terms of Use:</em> <a href="https://xagio.net/terms" rel="nofollow ugc">Xagio Panel Terms of Use</a></li>
<li><em>Privacy Policy:</em> <a href="https://xagio.net/privacy" rel="nofollow ugc">Xagio Panel Privacy Policy</a></li>
</ul>
<h3>Pixabay API</h3>
<ul>
<li><em>Purpose:</em> This service is used for sourcing royalty-free images to enhance content within the plugin.</li>
<li><em>Service URL:</em> <a href="https://pixabay.com/api/" rel="nofollow ugc">Pixabay</a></li>
<li><em>Terms of Use:</em> <a href="https://pixabay.com/service/terms/" rel="nofollow ugc">Pixabay Terms of Service</a></li>
<li><em>Privacy Policy:</em> <a href="https://pixabay.com/service/privacy/" rel="nofollow ugc">Pixabay Privacy Policy</a></li>
</ul>
<h3>YouTube Embeds</h3>
<ul>
<li><em>Purpose:</em> This service is used to embed YouTube videos within the plugin’s UI, allowing users to easily add video content to their websites, which can enhance SEO through multimedia content.</li>
<li><em>Service URL:</em> <a href="https://www.youtube.com" rel="nofollow ugc">YouTube</a></li>
<li><em>Terms of Use:</em> <a href="https://www.youtube.com/t/terms" rel="nofollow ugc">YouTube Terms of Use</a></li>
<li><em>Privacy Policy:</em> <a href="https://policies.google.com/privacy" rel="nofollow ugc">YouTube Privacy Policy</a></li>
</ul>
<h3>Tawk.to</h3>
<ul>
<li><em>Purpose:</em> This service is used for live chat support, enabling real-time communication between users and support teams.</li>
<li><em>Service URL:</em> <a href="https://tawk.to" rel="nofollow ugc">Tawk.to</a></li>
<li><em>Terms of Use:</em> <a href="https://www.tawk.to/terms-of-service/" rel="nofollow ugc">Tawk.to Terms of Use</a></li>
<li><em>Privacy Policy:</em> <a href="https://www.tawk.to/privacy-policy/" rel="nofollow ugc">Tawk.to Privacy Policy</a></li>
</ul>
<h3>Dropbox API</h3>
<ul>
<li><em>Purpose:</em> This service is used for cloud storage and retrieval of content files, including images and backups.</li>
<li><em>Service URLs:</em>
<ul>
<li><a href="https://content.dropboxapi.com" rel="nofollow ugc">Content API</a></li>
<li><a href="https://api.dropboxapi.com" rel="nofollow ugc">API</a></li>
</ul>
</li>
<li><em>Terms of Use:</em> <a href="https://www.dropbox.com/terms" rel="nofollow ugc">Dropbox Terms of Service</a></li>
<li><em>Privacy Policy:</em> <a href="https://www.dropbox.com/privacy" rel="nofollow ugc">Dropbox Privacy Policy</a></li>
</ul>
<h3>Google APIs</h3>
<ul>
<li><em>Purpose:</em> This service is used for various Google functionalities, including Google Search Console integration, Google Drive access, and Google Analytics tracking.</li>
<li><em>Service URLs:</em>
<ul>
<li><a href="https://www.googleapis.com" rel="nofollow ugc">Google APIs</a></li>
<li><a href="https://www.google.com" rel="nofollow ugc">Google</a></li>
</ul>
</li>
<li><em>Terms of Use:</em> <a href="https://policies.google.com/terms" rel="nofollow ugc">Google Terms of Service</a></li>
<li><em>Privacy Policy:</em> <a href="https://policies.google.com/privacy" rel="nofollow ugc">Google Privacy Policy</a></li>
</ul>
<h3>Microsoft Graph API</h3>
<ul>
<li><em>Purpose:</em> This service is used for integrating Microsoft services, including OneDrive and Microsoft Office 365.</li>
<li><em>Service URLs:</em>
<ul>
<li><a href="https://graph.microsoft.com" rel="nofollow ugc">Graph API</a></li>
</ul>
</li>
<li><em>Terms of Use:</em> <a href="https://www.microsoft.com/en-us/servicesagreement" rel="nofollow ugc">Microsoft Terms of Use</a></li>
<li><em>Privacy Policy:</em> <a href="https://privacy.microsoft.com/en-us/privacystatement" rel="nofollow ugc">Microsoft Privacy Policy</a></li>
</ul>
<h3>Microsoft Online Login</h3>
<ul>
<li><em>Purpose:</em> This service is used for authenticating users via Microsoft services, including Office 365 and OneDrive integrations within the plugin.</li>
<li><em>Service URL:</em> <a href="https://login.microsoftonline.com" rel="nofollow ugc">Microsoft Online Login</a></li>
<li><em>Terms of Use:</em> <a href="https://www.microsoft.com/en-us/servicesagreement" rel="nofollow ugc">Microsoft Online Terms of Service</a></li>
<li><em>Privacy Policy:</em> <a href="https://privacy.microsoft.com/en-us/privacystatement" rel="nofollow ugc">Microsoft Privacy Policy</a></li>
</ul>
<h3>Chrome Web Store</h3>
<ul>
<li><em>Purpose:</em> This service is used for distributing browser extensions associated with the plugin’s functionalities.</li>
<li><em>Service URL:</em> <a href="https://chromewebstore.google.com" rel="nofollow ugc">Chrome Web Store</a></li>
<li><em>Terms of Use:</em> <a href="https://www.google.com/chrome/privacy/eula_text.html" rel="nofollow ugc">Chrome Web Store Terms of Service</a></li>
<li><em>Privacy Policy:</em> <a href="https://policies.google.com/privacy" rel="nofollow ugc">Google Privacy Policy</a></li>
</ul>
<h3>Facebook APIs</h3>
<ul>
<li><em>Purpose:</em> This service is used for social media integration, including posting to Facebook and accessing Facebook Insights.</li>
<li><em>Service URLs:</em>
<ul>
<li><a href="https://www.facebook.com" rel="nofollow ugc">Facebook</a></li>
<li><a href="https://developers.facebook.com" rel="nofollow ugc">Developers</a></li>
</ul>
</li>
<li><em>Terms of Use:</em> <a href="https://www.facebook.com/terms.php" rel="nofollow ugc">Facebook Terms of Service</a></li>
<li><em>Privacy Policy:</em> <a href="https://www.facebook.com/policy.php" rel="nofollow ugc">Facebook Data Policy</a></li>
</ul>
<h3>W3C Validator</h3>
<ul>
<li><em>Purpose:</em> This service is used for validating the plugin’s generated HTML to ensure compliance with web standards.</li>
<li><em>Service URL:</em> <a href="http://www.w3.org" rel="nofollow ugc">W3C Validator</a></li>
<li><em>Terms of Use:</em> <a href="https://www.w3.org/Consortium/Legal/2015/terms-of-use" rel="nofollow ugc">W3C Terms of Service</a></li>
<li><em>Privacy Policy:</em> <a href="https://www.w3.org/Consortium/Legal/2015/privacy-statement" rel="nofollow ugc">W3C Privacy Policy</a></li>
</ul>
<h3>WordPress.org</h3>
<ul>
<li><em>Purpose:</em> This service is used for plugin updates, downloads, and API requests to the WordPress repository.</li>
<li><em>Service URLs:</em>
<ul>
<li><a href="https://wordpress.org" rel="ugc">WordPress</a></li>
<li><a href="https://downloads.wordpress.org" rel="nofollow ugc">Downloads</a></li>
<li><a href="http://api.wordpress.org" rel="nofollow ugc">API</a></li>
</ul>
</li>
<li><em>Terms of Use:</em> <a href="https://wordpress.org/about/privacy/" rel="ugc">WordPress Terms of Service</a></li>
<li><em>Privacy Policy:</em> <a href="https://wordpress.org/about/privacy/" rel="ugc">WordPress Privacy Policy</a></li>
</ul>
<h3>Bannerbear</h3>
<ul>
<li><em>Purpose:</em> This service is used for generating dynamic images and banners for SEO purposes.</li>
<li><em>Service URL:</em> <a href="https://www.bannerbear.com" rel="nofollow ugc">Bannerbear</a></li>
<li><em>Terms of Use:</em> <a href="https://www.bannerbear.com/terms/" rel="nofollow ugc">Bannerbear Terms of Service</a></li>
<li><em>Privacy Policy:</em> <a href="https://www.bannerbear.com/privacy/" rel="nofollow ugc">Bannerbear Privacy Policy</a></li>
</ul>
<h3>Schema.org</h3>
<ul>
<li><em>Purpose:</em> This service is used for structured data validation and schema generation to improve SEO.</li>
<li><em>Service URLs:</em>
<ul>
<li><a href="https://validator.schema.org" rel="nofollow ugc">Schema.org Validator</a></li>
<li><a href="http://schema.org" rel="nofollow ugc">Schema.org</a></li>
</ul>
</li>
<li><em>Terms of Use:</em> <a href="https://schema.org/docs/terms.html" rel="nofollow ugc">Schema.org Terms of Use</a></li>
<li><em>Privacy Policy:</em> <a href="https://schema.org/docs/privacy.html" rel="nofollow ugc">Schema.org Privacy Policy</a></li>
</ul>
<h3>Google Tag Manager</h3>
<ul>
<li><em>Purpose:</em> This service is used for managing and deploying marketing tags (snippets of code) on your website.</li>
<li><em>Service URL:</em> <a href="https://www.googletagmanager.com" rel="nofollow ugc">Google Tag Manager</a></li>
<li><em>Terms of Use:</em> <a href="https://marketingplatform.google.com/about/analytics/tag-manager/use-policy/" rel="nofollow ugc">Google Tag Manager Terms of Service</a></li>
<li><em>Privacy Policy:</em> <a href="https://policies.google.com/privacy" rel="nofollow ugc">Google Privacy Policy</a></li>
</ul>
<h3>Gravatar</h3>
<ul>
<li><em>Purpose:</em> This service is used for displaying user avatars in the plugin’s UI based on their email addresses.</li>
<li><em>Service URL:</em> <a href="https://gravatar.com/" rel="nofollow ugc">Gravatar</a></li>
<li><em>Terms of Use:</em> <a href="https://wordpress.com/tos/" rel="nofollow ugc">Gravatar Terms of Service</a></li>
<li>