CVE-2026-16618
ImproveSEO <= 2.0.11 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unauthenticated users to upload executable PHP files and achieve remote code execution.
| Vendor | unknown |
| Product | improve seo |
| Published | Aug 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown improve seo
Be the first to know when new unknown vulnerabilities affecting unknown improve seo are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Improve SEO
0 ≤ 2.0.11
References
Credits
João Ramos Maciel WPScan