CyberRota Analysis
AI-GeneratedThe SmartCrawl SEO plugin for WordPress versions prior to 3.16.3 is vulnerable due to insufficient capability checks on specific AJAX actions, enabling users with a Subscriber role to access the titles of private and draft posts by their IDs and enumerate post-meta key names. This exposure could lead to unauthorized information disclosure, compromising the confidentiality of sensitive content. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on two of its AJAX actions, allowing users with at least the Subscriber role to read the titles of private and draft posts by ID and to enumerate stored post-meta key names.