plugin

Smart Seo Tool Vulnerabilities

6 known security issues reported for the Smart Seo Tool WordPress plugin. Most recent disclosed Jul 23, 2026.

3 medium

Running Smart Seo Tool on your site? Check whether your installed version is affected.

Scan your site free

Smart SEO Tool – SEO优化插件 <= 4.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Smart SEO Tool – SEO优化插件 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scri...

CVSS:
6.4
Affected:
up to 4.1.2
Fix:
No patched version reported
Disclosed:
Jul 23, 2026

CVE-2026-65533 on NVD →

Smart SEO Tool &#8211; SEO优化插件 [smart-seo-tool] < 4.0.2

unknown

Update the WordPress Smart SEO Tool plugin to the latest available version (at least 4.0.2). WordFence discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Smart SEO Tool Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under th...

Affected:
up to 4.0.2
Fixed in:
4.0.2
Disclosed:
Aug 18, 2023

Smart SEO Tool-WordPress SEO优化插件 <= 4.0.1 - Cross-Site Request Forgery via 'wp_ajax_wb_smart_seo_tool'

medium

The Smart SEO Tool-WordPress SEO优化插件 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.1. This is due to missing or incorrect nonce validation on the 'wp_ajax_wb_smart_seo_tool' function. This makes it possible for unauthenticated attackers to modify the plugin's...

CVSS:
5.4
Affected:
up to 4.0.2
Fixed in:
4.0.2
Disclosed:
Aug 16, 2023

Smart SEO Tool &#8211; SEO优化插件 [smart-seo-tool] < 4.0.2

unknown

The Smart SEO Tool-WordPress SEO优化插件 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.1. This is due to missing or incorrect nonce validation on the 'wp_ajax_wb_smart_seo_tool' function. This makes it possible for unauthenticated attackers to modify the plugin's...

Affected:
up to 4.0.2
Fixed in:
4.0.2
Disclosed:
Aug 16, 2023

Smart SEO Tool &#8211; SEO优化插件 [smart-seo-tool] < 3.0.6

unknown

[en] The Smart SEO Tool WordPress plugin before 3.0.6 does not sanitise and escape the search parameter before outputting it back in an attribute when the TDK optimisation setting is enabled, leading to a Reflected Cross-Site Scripting

Affected:
up to 3.0.6
Fixed in:
3.0.6
Disclosed:
Jan 24, 2022

CVE-2021-24976 on NVD →

Smart SEO Tool <= 3.0.5 - Reflected Cross-Site Scripting

medium

The Smart SEO Tool WordPress plugin before 3.0.6 does not sanitise and escape the search parameter before outputting it back in an attribute when the TDK optimisation setting is enabled, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 3.0.6
Fixed in:
3.0.6
Disclosed:
Dec 22, 2021

CVE-2021-24976 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database