Smart SEO Tool – SEO优化插件 <= 4.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Smart SEO Tool – SEO优化插件 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scri...
- CVSS:
- 6.4
- Affected:
- up to 4.1.2
- Fix:
- No patched version reported
- Disclosed:
- Jul 23, 2026
CVE-2026-65533 on NVD →
Smart SEO Tool – SEO优化插件 [smart-seo-tool] < 4.0.2
unknown
Update the WordPress Smart SEO Tool plugin to the latest available version (at least 4.0.2).
WordFence discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Smart SEO Tool Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under th...
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.2
- Disclosed:
- Aug 18, 2023
Smart SEO Tool-WordPress SEO优化插件 <= 4.0.1 - Cross-Site Request Forgery via 'wp_ajax_wb_smart_seo_tool'
medium
The Smart SEO Tool-WordPress SEO优化插件 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.1. This is due to missing or incorrect nonce validation on the 'wp_ajax_wb_smart_seo_tool' function. This makes it possible for unauthenticated attackers to modify the plugin's...
- CVSS:
- 5.4
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.2
- Disclosed:
- Aug 16, 2023
Smart SEO Tool – SEO优化插件 [smart-seo-tool] < 4.0.2
unknown
The Smart SEO Tool-WordPress SEO优化插件 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.1. This is due to missing or incorrect nonce validation on the 'wp_ajax_wb_smart_seo_tool' function. This makes it possible for unauthenticated attackers to modify the plugin's...
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.2
- Disclosed:
- Aug 16, 2023
Smart SEO Tool – SEO优化插件 [smart-seo-tool] < 3.0.6
unknown
[en] The Smart SEO Tool WordPress plugin before 3.0.6 does not sanitise and escape the search parameter before outputting it back in an attribute when the TDK optimisation setting is enabled, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.6
- Disclosed:
- Jan 24, 2022
CVE-2021-24976 on NVD →
Smart SEO Tool <= 3.0.5 - Reflected Cross-Site Scripting
medium
The Smart SEO Tool WordPress plugin before 3.0.6 does not sanitise and escape the search parameter before outputting it back in an attribute when the TDK optimisation setting is enabled, leading to a Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 3.0.6
- Fixed in:
- 3.0.6
- Disclosed:
- Dec 22, 2021
CVE-2021-24976 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database