PT-2025-37022 · WordPress · Wp Blast | Seo & Performance Booster

Nabil Irawan

·

Published

2025-09-10

·

Updated

2025-09-10

·

CVE-2025-9622

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: WP Blast | SEO & Performance Booster plugin for WordPress versions up to and including 1.8.6
Description: The WP Blast | SEO & Performance Booster plugin for WordPress is susceptible to Cross-Site Request Forgery due to missing or incorrect nonce validation on multiple administrative actions within the Settings class. This allows unauthenticated attackers to trigger actions such as cache purging, sitemap clearing, plugin data purging, and score resetting by tricking a site administrator into performing an action.
Recommendations: Update the WP Blast | SEO & Performance Booster plugin to a version newer than 1.8.6.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-9622

Affected Products

Wp Blast | Seo & Performance Booster