SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-16979

MEDIUM · CVSS 4.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The SmartCrawl SEO plugin for WordPress versions prior to 3.16.3 is vulnerable due to insufficient capability checks on specific AJAX actions, enabling users with a Subscriber role to access the titles of private and draft posts by their IDs and enumerate post-meta key names. This exposure could lead to unauthorized information disclosure, compromising the confidentiality of sensitive content. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-16979
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%
WordPress

Original NVD Description

The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names.