SmartCrawl SEO checker, analyzer & optimizer < 3.16.3 - Missing Authorization
medium
The SmartCrawl SEO checker, analyzer & optimizer plugin for WordPress is vulnerable to unauthorized access in all versions up to 3.16.3. This is due to a missing capability check on a function. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.16.3
- Fixed in:
- 3.16.3
- Disclosed:
- Aug 21, 2026
CVE-2026-16979 on NVD →
SmartCrawl <= 3.14.3 - Missing Authorization
medium
The SmartCrawl SEO checker, analyzer & optimizer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.14.3. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized...
- CVSS:
- 4.3
- Affected:
- up to 3.14.3
- Fixed in:
- 3.14.4
- Disclosed:
- Oct 16, 2025
CVE-2025-62048 on NVD →
SmartCrawl SEO checker, analyzer & optimizer <= 3.14.3 - Missing Authorization to Plugin Settings Update
medium
The SmartCrawl SEO checker, analyzer & optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_submodule() function in all versions up to, and including, 3.14.3. This makes it possible for authenticated attackers, with Subscriber-level access and...
- CVSS:
- 4.3
- Affected:
- up to 3.14.3
- Fixed in:
- 3.14.4
- Disclosed:
- Sep 29, 2025
CVE-2025-11163 on NVD →
SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer <= 3.10.8 - Unauthenticated Full Path Disclosure
medium
The SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.10.8. This is due the plugin utilizing mobiledetect without preventing direct access to the files. This makes it possible for unauthenticated attackers to...
- CVSS:
- 5.3
- Affected:
- up to 3.10.8
- Fixed in:
- 3.10.9
- Disclosed:
- Jul 9, 2024
CVE-2024-6556 on NVD →
SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer <= 3.10.2 - Missing Authorization
medium
The SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer plugin for WordPress is vulnerable to unauthorized ld+json description injection due to a missing capability check on the save_settings function in all versions up to, and including, 3.10.2. This makes it possible for unauthenticated attackers to save sc...
- CVSS:
- 5.3
- Affected:
- up to 3.10.2
- Fixed in:
- 3.10.3
- Disclosed:
- Apr 19, 2024
CVE-2024-3287 on NVD →
Simple Social Media Share Buttons <= 3.8.2 - Unauthenticated Password Protected Post Disclosure
medium
The Simple Social Media Share Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.2 via meta tags. This makes it possible for unauthenticated attackers to retrieve data from password protected posts that may have sensitive information.
- CVSS:
- 5.3
- Affected:
- up to 3.8.3
- Fixed in:
- 3.8.3
- Disclosed:
- Nov 23, 2023
CVE-2023-5949 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database