🔐 CVE Alert

CVE-2026-16618

UNKNOWN 0.0

ImproveSEO <= 2.0.11 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unauthenticated users to upload executable PHP files and achieve remote code execution.

Vendor unknown
Product improve seo
Published Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for unknown improve seo

Be the first to know when new unknown vulnerabilities affecting unknown improve seo are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Improve SEO
0 ≤ 2.0.11

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/3754d4c0-1b67-49a4-a29a-7169446638d1/

Credits

João Ramos Maciel WPScan